Stay connected with KayaToday, follow us on Instagram and Facebook for the latest news and reviews delivered straight to you.
Cold storage wallets have long been sold as the gold standard of Bitcoin security, the safest place to keep digital assets precisely because they stay offline. The ongoing Coldcard exploit is forcing a serious reassessment of that assumption, and the numbers keep getting worse.
Galaxy Digital’s head of research, Alex Thorn, confirmed on Tuesday that at least 15 distinct attackers have now been identified in connection with the Coldcard vulnerability, a figure that has grown as new victim reports continue to surface. Estimated losses have reached $100 million across three confirmed attack waves, with a suspected fourth wave potentially pushing total losses to around $130 million in Bitcoin.
Why Each New Victim Report Reveals a Bigger Attack
One of the more striking details Thorn shared is how victim reports are actively expanding the picture of the exploit’s scale. Because this was not a breach of a centralised exchange, where a single database leak exposes everything at once, the attack unfolded across many individual wallets in ways that were initially invisible. Each report helps investigators connect previously unlinked addresses to known attackers.
Thorn illustrated this with a concrete example on X: “Due to one single victim’s report of less than 1 BTC stolen, we identified a new attack with 12 BTC siphoned from 126 addresses.” That ratio, where one small report unlocks evidence of a much larger theft, suggests the true scope of the exploit may still be underestimated. Galaxy Research has now labelled new attackers that would have gone undetected without those individual disclosures.
The incident has reignited a longstanding debate in the crypto community about whether self-custody is genuinely safer than keeping assets on a reputable exchange. For years, the standard advice has been “not your keys, not your coins.” But a hardware wallet vulnerability that can be exploited at scale complicates that calculus significantly.
The AI Angle Is Real, but the Hype Needs Trimming
Alongside the financial damage, a parallel argument has broken out over whether artificial intelligence tools could have caught this vulnerability before attackers did, and whether AI is now lowering the barrier to finding such flaws in the first place.
Dragonfly managing partner Haseeb Qureshi argued that roughly “$2 of AI hardening” could have prevented the exploit, pointing to social media reports claiming that some AI models were able to rediscover the underlying vulnerability in under 20 minutes. Qureshi noted that open-source model GLM 5.2 reportedly reproduced the attack in 20 minutes with web access disabled, which he cited as the more credible test, while acknowledging that other claims about Claude doing it in eight minutes may have been contaminated by web search results.
Those more dramatic claims deserve scrutiny. Tatsapat Saerejittima, data lead at crypto analytics platform Tokenomist, told Cointelegraph that the viral assertion about AI finding the vulnerability in two minutes originated from a pseudonymous Reddit user who scanned the code only after the vulnerability had already become public knowledge. “There was no blind test, no documented methodology, and no assessment of the model’s false-positive rate,” he said. In other words, asking an AI to find a flaw after the flaw has been publicly described is a very different exercise from discovering it independently in the wild.
That said, dismissing the AI dimension entirely would also be a mistake.
A Firmware Bug Made the Underlying Entropy Far Too Weak
Castle Labs co-founder Francesco, who asked Cointelegraph not to publish his surname, pointed to a specific technical failure at the heart of the Coldcard vulnerability. The device used a level of private key entropy of just 40 bits, far below the 128-bit entropy standard that a 12-word seed phrase provides in most other wallets. This was the result of a firmware bug, and it made the job of reconstructing private keys substantially easier for anyone attempting to do so.
Francesco acknowledged that growing AI capabilities are already reducing the cost and time required to discover new cryptocurrency vulnerabilities. He expects that trend to continue as AI models become more capable and more widely used in both defensive cybersecurity and offensive exploit development. The implication is uncomfortable: the same tools that could help developers audit their code are also available to the people looking to break it.
For investors and businesses in Malaysia and Singapore holding Bitcoin through hardware wallets, the Coldcard episode is a reminder that “cold storage” is not a monolithic guarantee of safety. The security of any hardware wallet depends on the quality of its firmware, the strength of its key generation, and the speed with which its developers identify and patch weaknesses. Regulators including the Securities Commission Malaysia and the Monetary Authority of Singapore have consistently emphasised the risks of self-custody for retail investors, and this incident gives those warnings fresh weight.
Why the Cost of the Next Exploit Could Be Lower
The broader lesson from Coldcard is not simply that one wallet had a bug. It is that the economics of finding and exploiting such bugs are shifting. If AI tools can meaningfully accelerate vulnerability discovery, even with the important caveats around methodology and false positives, then the window between a flaw being introduced and a flaw being weaponised may be shrinking. Developers who once had months to catch a mistake in a firmware release may soon have far less time.
For the hardware wallet industry, that means the pressure to adopt rigorous, AI-assisted code auditing before release is no longer optional. For users, it means that the due diligence required before trusting any self-custody solution has to go deeper than brand reputation alone. And for the wider crypto ecosystem, the Coldcard exploit serves as a live demonstration that decentralisation does not automatically mean security, especially when the weakest link is a few lines of flawed firmware sitting inside a device that millions of people trust with their savings.
Read More: Strategy Holds STRC Dividend at 12% Even as Shares Languish Below Par