The Coldcard Hack Is Bigger Than Anyone Admitted, and Galaxy Says Count on It Getting Worse

Galaxy Research believes the total losses from the Coldcard hardware wallet exploit could swell to $130 million, once a fourth wave of attacks, still unconfirmed, is folded into the final tally.

That number is not a worst-case scenario. According to Galaxy's post on X, it is the expected outcome once investigators finish mapping the full scope of the breach. The figure already dwarfs earlier estimates, and the fourth wave hasn't even been officially confirmed yet.

What We Know So Far

Coldcard is one of the most trusted names in Bitcoin self-custody. It is the wallet security-conscious holders buy specifically because they do not trust exchanges or software wallets. The fact that an exploit of this scale hit Coldcard is not just a financial story. It is a confidence crisis for the entire hardware wallet category.

Galaxy's analysis points to multiple coordinated attack waves, suggesting this was not an opportunistic smash-and-grab. The structure implies planning, patience, and knowledge of how Coldcard users behave. That detail matters more than the dollar figure.

Why the Fourth Wave Changes Everything

When researchers flag an unconfirmed wave of attacks, it typically means one of two things: either the exploit vector is still active, or the attacker extracted funds slowly enough that on-chain forensics haven't fully caught up yet. Neither scenario is comforting.

If the attack surface is still open, any Coldcard user who hasn't moved funds is potentially still exposed. If the losses are still being discovered weeks later, the final number could move above $130 million before the story is closed.

Galaxy's framing, specifically calling out the fourth wave as "yet-unconfirmed" rather than "ruled out," signals that investigators are treating it as probable, not speculative.

What Bitcoin Holders Should Do Right Now

This is not a "watch and wait" situation. If you hold Bitcoin on a Coldcard device, especially an older firmware version, the immediate move is to check Coldcard's official channels for any security advisories and consider transferring funds to a freshly generated wallet on verified, updated firmware.

More broadly, this story is a reminder that hardware wallet security is not a one-time setup. Firmware updates exist for a reason. Seed phrase hygiene matters. And trusting a device because it has a good reputation is not the same as auditing whether your specific setup is still safe.

Watch for Galaxy's full report once the fourth wave is confirmed or ruled out. That update will either cap the damage at $130 million or push this into territory that forces the entire hardware wallet industry to answer hard questions publicly.