Security researchers at Galaxy Research revealed that suspected thefts involving Coldcard seeds now total 1,367.05 BTC spread across 4,585 addresses. This figure rose sharply with the discovery of a third cluster of attacks, adding 207.7294 BTC and pushing estimated losses well beyond the initial $38 million estimate.

The root of the compromise lies in a flaw that reduced randomness in the seed generation process. This vulnerability allowed attackers to exploit Coldcard wallets despite their offline storage and air-gapped protections, traditionally considered strong security measures.

Firmware updates and user caution

Coldcard has released firmware updates that secure seed generation for new wallets, but owners of existing seeds remain exposed unless they migrate to fresh backups. This incident highlights a rare but critical weakness in hardware wallet security, challenging assumptions about offline protection reliability.

Experts warn that users relying solely on offline backups or air-gapped devices should verify their device firmware and consider re-securing their funds. The evolving cluster of incidents suggests attackers continue refining methods to exploit subtle cryptographic flaws.

This material is for informational purposes only, not financial advice.