Scope of Exploitation Grows
At least 15 different attackers have leveraged a Coldcard vulnerability to drain cryptocurrency holdings, according to analysis by Galaxy Digital. The exploit has resulted in approximately $114 million to $130 million in losses across multiple incidents, with the underlying flaw remaining active on vulnerable device models and firmware versions, according to CoinDesk.
Security researchers at Dragonfly noted that the vulnerability could have been mitigated with what amounts to minimal hardening measures, suggesting the exploit represented a preventable security gap. The continued exposure of certain Coldcard devices has prompted the company to urge users to move their bitcoin to alternative custody solutions immediately.
Secondary Threats Emerge as Exploit Persists
As the original exploit continues circulating, hardware wallet firms are warning of a coordinated phishing campaign targeting Coldcard users. According to Decrypt, threat actors are sending fake "hardware audit" emails directing victims to a counterfeit Coldcard website designed to install remote-access software, effectively creating a second attack vector against already-compromised users.



