Galaxy Research has identified that 1,367 Bitcoin were drained in attacks targeting Coldcard hardware wallet addresses. The findings, released this week, underscore serious security gaps in devices long considered the gold standard for cold storage.
Hardware wallets are meant to keep private keys offline, safe from remote hacks. But the Coldcard breach shows that even these supposedly tamper-proof devices can be exploited. The researchers did not specify how the attackers pulled off the theft, but the scale — more than $40 million at current prices — makes it one of the larger hardware wallet incidents on record.
What the data shows
Galaxy Research analyzed blockchain transactions and traced 1,367 BTC moving out of Coldcard addresses. The company behind Coldcard, which markets the device as “the most secure Bitcoin hardware wallet,” has not yet commented on the report. The researchers said the attacks likely exploited vulnerabilities in the device’s firmware or in the way users generated and stored their seed phrases.
Coldcard wallets use a secure element chip and offer features like air-gapped signing. But the drain suggests that attackers found a way to bypass those protections. Whether the breach was a single coordinated attack or a series of smaller incidents remains unclear.
Hardware wallets are widely recommended by security experts as the safest way to store cryptocurrency. The Coldcard incident challenges that assumption. If a device built specifically for security can be compromised, then no storage method is completely risk-free.
Users who rely on Coldcard wallets are now left wondering if their funds are safe. The researchers did not name specific victims or say whether the stolen BTC belonged to individuals or institutions. But the sheer volume suggests that at least some of the affected parties were high-value targets.
What Coldcard users should do
Without an official statement from the manufacturer, users are in a holding pattern. Galaxy Research recommends that Coldcard owners review their transaction history and consider moving funds to a new wallet with a fresh seed phrase generated on a clean device. They also advise against using any Coldcard that may have been tampered with during shipping or that was purchased from an untrusted reseller.
The researchers did not provide a timeline for when they first detected the drain or whether the vulnerability has been patched. That leaves a key question unanswered: is the attack still ongoing?
For now, the Bitcoin community is waiting for Coldcard’s parent company to respond. A detailed post-mortem from Galaxy Research is expected in the coming weeks, which may shed light on the exact method used. Until then, the 1,367 BTC — and the security of every Coldcard wallet — hang in the balance.




