1,367 BTC Gone From Coldcard Addresses: The Hardware Wallet Is a Beacon, Not a Shield

CryptoPomp โ€ข โ€ข Flash News
1,367 BTC. Let the forensic math land: at a conservative $65,000 per coin, that is $88.8 million. At the 2025 highs, it clears nine figures and keeps walking. This is not a phishing email that tricked a tourist into surrendering a seed phrase on a fake website. This is Galaxy Research โ€” the on-chain intelligence arm of Mike Novogratz's digital asset empire โ€” going public with the news that the most paranoid slice of Bitcoin's self-custody population, the Coldcard crowd, lost over a thousand coins from their supposedly air-gapped, military-grade, "the paranoid's choice" fortresses. Stop. Re-read that last sentence. The attacker did not raid an exchange hot wallet. They did not drain a bridge contract. They went after the segment of the market that bought a device specifically designed to never touch a networked computer. A device with signed firmware, tamper-evident seals, and a design philosophy that treats USB cables as a potential assassination vector. And they won. The question is not how much 1,367 BTC is worth. The question is: how did the attacker know where to look? And here is the detail that should make every hardware wallet vendor on the planet break into a cold sweat: Galaxy Research did not say "Coldcard was hacked." They said "attacks on Coldcard addresses." That is not a casual turn of phrase. That is forensic curation. Someone at Galaxy Research looked at the chain, saw a pattern, and concluded these were Coldcard-derived addresses before tracing the drain. The device may be intact. The cryptographic primitives โ€” BIP39, BIP32, the elliptic curve math itself โ€” may be pristine. But the population using those devices just became a visible, targetable cluster. In eighteen years of watching this industry evolve, that distinction โ€” between "the device was compromised" and "the user population was identified and attacked" โ€” is the most important detail in this entire story. And almost nobody is talking about it. Let me establish what Coldcard actually is, because the gravity of this event depends on understanding the product's place in the ecosystem. Coldcard is manufactured by Coinkite, a Canadian hardware company that has cultivated a deliberately austere brand. No fancy screens with pixel-art animations. No Bluetooth. No wireless connectivity of any kind. Coldcard is a device with a monochrome display, a numeric keypad, and a firmware written with an almost religious commitment to transparency. The source code is open. The bootloader is signed. The device will display a random seed generated entirely offline and warn you โ€” repeatedly, almost obnoxiously โ€” to never enter it into anything connected to the internet. This is the wallet of choice for the Bitcoin priesthood. The people who run their own nodes, who use coinjoin, who refuse to touch an exchange unless absolutely necessary. Coldcard has also become the default hardware recommendation from a growing ecosystem of bitcoin-native financial infrastructure โ€” collaborative custody services like Unchained and Casa, whose multi-sig products often feature Coldcard as a primary signing device. The security model is deceptively simple: the private key is generated on-device, stored on the device's secure element, and used to sign transactions offline. The signed transaction is then transferred โ€” via microSD card, or via a QR code, or via a USB connection that the user explicitly authorizes โ€” to a computer that broadcasts it. The private key, in theory, never touches a networked device. In the threat model, the attacker must either physically possess the device, break the cryptography of the signatures, or compromise the user's operational security around the device. That is the promise. That is what 1,367 BTC just called into question. The market context matters here. We are in 2025, in a bull market that has once again made self-custody fashionable. The post-FTX lesson โ€” "not your keys, not your coins" โ€” has moved from cypherpunk slogan to mainstream investor mantra. Coldcard, as the most ideological hardware wallet on the market, has been a direct beneficiary. And bull markets are precisely when security complacency inflates. When the portfolio is up 40%, the urge to move coins around, to calculate profits, to tinker with yield products, all of that psychological friction creates the exact operational errors that this kind of attack feeds on. So the timing, as always in this industry, is not a coincidence. The attack vector and the market cycle rhyme. Now let us do the forensic work. What do we actually know? First, the number itself: 1,367 BTC. At current prices, that is roughly between $85 million and $110 million depending on the exact price at the time of the report. By historical standards, this is a mid-sized crypto heist โ€” smaller than the $600 million Ronin bridge hack, smaller than the $190 million Nomad bridge exploit โ€” but calling it "mid-sized" when measured against the total volume of Bitcoin trading is misleading. We are talking about the loss of 0.0065% of Bitcoin's circulating supply. Against a daily spot volume that regularly clears $20 billion, the direct sell-pressure impact of this sum is a rounding error. But raw price impact is the wrong lens. Here is the thing about 1,367 BTC: it is an aggregation. The language of Galaxy Research's announcement โ€” "attacks on Coldcard addresses" โ€” is plural in a way that suggests distributed losses across multiple victims, not a single whale getting picked off. And that distribution fingerprint tells us something critical about the adversary. If this were a single-target attack โ€” a wealthy founder, a fund with a known cold storage protocol โ€” you would expect a single address or a tightly connected cluster of addresses draining in one dramatic sweep. That is a surgical strike. Distributed losses across multiple addresses is something else entirely. That is a campaign. It implies the attacker either identified a segment of the user population and systematically picked them off, or they discovered a degradation in a shared security control and harvested it. Let me be precise about the information gaps, because any analyst who claims to know exactly what happened here is lying. Galaxy Research has not published the full report. We do not have the attack window, the transaction hashes, the destination addresses, or a confirmation of the mechanism. We have a headline number and the phrase "Coldcard addresses." So what we are doing here is evaluating hypotheses โ€” and ranking them by how well they fit the available evidence. Hypothesis one: the user got compromised. This is the industry's default answer for almost every hardware wallet incident, and it is not wrong โ€” most of the time. The attack surface of a hardware wallet user is much larger than the device itself. Consider the workflow. To update firmware, a user must download the signed firmware image from Coinkite's website, verify the cryptographic signature, and transfer it to the device over USB or microSD. To broadcast a signed transaction, the user must interact with a desktop wallet like Sparrow or Specter, which themselves are software running on a networked computer. To back up the wallet, the user must record a 24-word seed phrase on paper or metal, and that seed has lived in the user's hands, in the user's home, in the user's safe. Attackers know all of this. The actual vulnerable perimeter in most hardware wallet setups is not the silicon. It is the human being โ€” and the software that human being uses. The vectors under this hypothesis are numerous. A counterfeit or modified version of the desktop wallet that steals the unsigned transaction data is a target. A phishing site that looks like Coinkite's and serves a malicious firmware download is a target. A compromised seed-phrase backup โ€” say, a photo stored in an insecure cloud, or text typed into a Google Doc "for safekeeping" โ€” is a target. And let us not forget the social engineering angle: the fake support agent, the "you have been compromised, please verify your seed phrase" phone call, or the fake wallet-recovery tool that genuinely looks useful. Based on my audit experience in this industry, I can tell you with high confidence that the percentage of hardware wallet losses caused by true cryptographic breaks is vanishingly small. The overwhelming majority of these incidents are operations failures: user error, social engineering, or contaminated software in the wallet ecosystem. But here is the problem with defaulting to this hypothesis: it does not explain why these specific attacks were attributed to Coldcard addresses. A social engineering attack on a Bitcoin user does not care whether the victim owns a Coldcard or a Ledger. A fake firmware site does not specifically target one device brand. If this were purely a human-perimeter attack, we would expect Galaxy Research to report "1,367 BTC drained from a defined cohort of self-custody users" โ€” not a specific hardware wallet attribution. So either the attackers did their homework and specifically targeted Coldcard users who exhibited identifiable behaviors, or there is something more systemic at play. Hypothesis two: the supply chain was compromised. This is the nightmare scenario for every hardware wallet vendor. You can have the most mathematically perfect firmware, the strongest secure element, the most paranoid design process on Earth โ€” and it all becomes meaningless if the device is tampered with before it reaches the customer's hands. The hardware supply chain is astonishingly opaque. Chips are fabricated in foundries half a world away. Assembly happens in factories under contracts. Firmware is flashed at unknown stages. Devices transit through logistics hubs, warehouses, customs checkpoints. At every one of these stages, a motivated attacker โ€” particularly a well-resourced one, or a nation-state actor โ€” has an opportunity to insert a malicious component. Coldcard's defense against this is among the most robust in the industry. Coinkite's devices ship with tamper-evident seals. The firmware is signed and verified on boot. The secure element is designed to resist physical key extraction. The company's entire brand is built around the commitment that you can verify your device has not been touched. But no seal is impenetrable. A sophisticated adversary could, in theory, intercept a batch of devices, replace the secure element with a malicious variant, install a modified firmware that appears to verify correctly, and re-seal the packaging with equipment that replicates the original. The user, two weeks later, plugs in the device, sees the legitimate boot screen, generates what they believe is a secure seed โ€” and in reality, the seed has been exfiltrated to a server controlled by the attackers. Low confidence here, I will be clear about that. This hypothesis requires a very high level of adversary sophistication. But it is precisely the scenario that a warning phrase like "attacks on Coldcard addresses" cannot rule out. And it is the scenario with the most devastating implications: a successful supply-chain attack against one hardware vendor damages the entire self-custody industry's credibility, not just one product. And then there is hypothesis three. The one that has been quietly bothering me since the report dropped. The one that makes this story an evolution, not an incident. The idea that addresses themselves carry identifying fingerprints โ€” and that those fingerprints are visible on-chain. Think about what the phrase "Coldcard addresses" actually means from a research perspective. Galaxy Research claims to have identified 1,367 BTC leaving addresses belonging to Coldcard users. How would they know? What does a "Coldcard address" look like? The answer is: subtle. Bitcoin addresses are not labeled at the protocol level. But they carry structural signatures. The type of address (BIP49 wrapped SegWit p2sh, BIP84 native SegWit bech32, BIP86 taproot). The derivation path patterns used. The way change outputs are handled. The transaction ordering patterns relative to the user's other inputs. The behavioral clustering โ€” how the coins were acquired, how long they sat, whether they were consolidated, whether they were spent in a way that is typical of a specific wallet software's coin-selection algorithm. Coldcard, as it happens, has some distinctive behavioral fingerprints. The device's coin-control features, its approach to change address management, its integration with specific desktop wallets โ€” each of these creates patterns that an analyst running clustering software can detect. If you know what you are looking for, you can build a classifier that tags addresses as "high probability Coldcard-derived." Now, take that capability and aim it at the entire Bitcoin network. You are not just identifying wallet software for academic interest. You are building a list of potential victims. Users who have demonstrated that they hold significant amounts of a non-custodial asset โ€” a hard, physical limit on their extractable wealth โ€” and who have parked that wealth in an infrastructure that has a known attack surface. This is not a vulnerability in Coldcard's cryptography. It is a vulnerability in the entire marketplace of ideas around self-custody. The hardware wallet was supposed to make you cryptographically unassailable. It did not account for the fact that the blockchain itself is a surveillance instrument, and that your choice of security hardware is a metadata signal you transmit to anyone who knows how to read it. This, more than any firmware exploit, is why the phrase "attacks on Coldcard addresses" should put ice in the industry's veins. It suggests the attack started with identification. Now let me put the attacker under the microscope for a moment, because the details of the theft reveal a lot about who we are dealing with. The stolen amount โ€” 1,367 BTC โ€” is large but not maximal. The distribution of losses suggests they went for breadth rather than living on a single kill. That is a deliberate trade-off. Going after a single massive target carries higher rewards but also higher operational risk; the loss of a single whale attracts intense scrutiny. Spreading the attack across many targets reduces the signal-to-noise ratio for investigators, buys the attacker time, and makes it harder for the community to rally around a single victim. The patience required here is also telling. If the attack was a campaign unfolding over weeks or months, the perpetrator had to maintain operational security across billions of potentially traceable transactions. Any movement of the funds creates a trail. Any exchange deposit creates a potential KYC breach. The fact that this campaign apparently ran long enough to drain 1,367 BTC without prior industry-wide warning is a mark of disciplined tradecraft. There is also a timing question that deserves attention. Why now? If the attack campaign has been running for months, why did Galaxy Research choose this moment to go public? The most likely answer is that they had either just completed their analysis or the attack reached a scale that could no longer be quietly ignored. Research shops do not make these announcements for fun. They make them because the window between "the market can absorb this" and "the market discovers it anyway" is a strategic resource. And here is a darker possibility we cannot dismiss: that Galaxy Research identified not a single attacker, but multiple attackers who independently discovered the same Coldcard-related weakness and started exploiting it simultaneously. The number 1,367 could be a composite of several campaigns. That scenario โ€” an attack pattern becoming commoditized across multiple criminal groups โ€” is precisely what precedes a dramatic industry-wide shift. The economics of the attack deserve their own paragraph. A hardware wallet attack requires upfront investment: research, either on-chain fingerprinting or supply chain infiltration or phishing infrastructure; the operational cost of running the campaign; and the risk-adjusted cost of potential detection. The payoffs, at 1,367 BTC, are significant enough to fund the next generation of attacks. In the criminal world, a successful campaign is not an endpoint โ€” it is a business model. The same playbook will be reused, refined, and sold. The next victim cohort may not use Coldcard; they may use any hardware wallet with identifiable fingerprints. The lesson has been learned by the entire criminal ecosystem. There is also a deeper financial-system implication that most coverage has missed: the insurance angle. Cyber insurance for digital assets has been a growing sector, with premiums calibrating to the perceived risk of custody solutions. A successful hardware-wallet-scale attack gives underwriters a new data point. Institutional investors who had been confident that self-custody protocols were "good enough" will now face higher insurance premiums or outright exclusions for hardware-only custody setups. That may push capital toward regulated custodians โ€” not because the custodians are more secure, but because their risk is more insurable. This is the quiet, structural force that will reshape the market far more than the immediate price reaction. Here is something else I have not seen anyone in the mainstream coverage bring up. And it is almost certainly because it would complicate their preferred narrative. If the victims of this attack โ€” the individual Coldcard users โ€” had followed the most paranoid version of self-custody best practices, a 2-of-3 multi-signature setup with signing devices from different vendors, the attack outcome would have looked very different. Compromise one device and the attacker still needs the other two. Compromise a single hardware wallet's supply chain and the multi-sig structure creates a speed bump that most attackers cannot overcome. The fact that the attacker managed to drain 1,367 BTC suggests that a significant portion of the victim cohort were operating single-signature setups, with everything on one device. That should raise an uncomfortable question: how many of the victims were "ruthlessly paranoid" Coldcard maximalists who had rejected the concept of multi-sig as overkill? And how much of the self-custody movement, which has spent years championing the singularity of the hardware wallet, is now facing the consequences of its own oversimplification? I wrote about the DeFi composability era with a similar lens back in 2020 โ€” the industry's habit of overselling a simplified version of risk. The impermanent loss debate was the same pattern: a complex risk that was marketed as a feature until it bit people, and then the narrative had to scramble to absorb the failure. We are now watching the same cycle play out in hardware wallets. The "one device, total security" narrative has been exposed as incomplete. The evolution of the story โ€” the part that matters โ€” is whether this event accelerates the shift to multi-sig, or whether the industry responds by burying the nuance and insisting that "Coldcard is fine, the users failed." Let me bring this down to something more personal for a moment, because I have been in this industry long enough to have watched several iterations of this exact psychological dance. I was a junior analyst in Tokyo during the 2017 ICO boom, the guy parsing whitepapers at 2am, known for speed over perfect accuracy. I learned the hard way that the fastest interpretations are rarely the deepest ones. In DeFi Summer of 2020, I wrote my famous thread on impermanent loss โ€” arguing it was a feature, not a bug, for liquidity providers. The pushback taught me that the people screaming the loudest about security are often the most vulnerable to narrative trapdoors. We did not understand the full risk surface of hardware wallets back then, any more than the wider community did. The 2022 collapse taught us the brutal lesson that centralization was the systemic fault line โ€” and that the reflexive answer, "just self-custody it on a hardware wallet," was itself an incomplete answer. I have spent the years since auditing wallet workflows, talking to the engineers at Coinkite and their competitors, and watching the threat model evolve. Here is what I can tell you from that experience: the gap between "the device is secure" and "the user's total system is secure" is massive, and it is where almost every material loss actually happens. The user's total system includes the desktop wallet, the firmware update path, the seed backup process, the physical security of the home, the phishing resistance of the user's own mind, and โ€” increasingly โ€” the metadata trail that connects all of these to a specific individual on-chain. Attackers do not break the cryptography. They study the workflow, find the step where human behavior contaminates perfection, and strike. The contrarian read on this event, and the one I want to stay with, is this: the hardware wallet is a beacon, not a shield. Its purpose was to make private keys unhackable. But in doing so, it made the user population โ€” and their addresses โ€” dramatically more visible. And visibility is the precursor to targeting. The entire self-custody narrative, wrapped as it is in libertarian mythology, has a structural blind spot. It treats the blockchain as an immutable ledger โ€” which it is โ€” but fails to treat it as a total surveillance network โ€” which it also is. Every transaction you make, every address you generate, every coin you consolidate, is being read by an archipelago of intelligence-gathering systems: chain analysis firms, national security agencies, and increasingly, well-funded criminal networks. The hardware wallet secures the key. But the metadata around the key โ€” who owns it, where it lives, how it behaves โ€” is an open book. In other words, the industry's focus on cryptographic defense has created a targeting vulnerability. It is as if the world's most secure bank vault had a lighthouse bolted to its roof, and the burglars simply waited for the beam to reveal the location of the safe. And the market's reaction to this will almost certainly be a misread. On one side, the Bitcoin maximalist community will circle the wagons and insist that Coldcard's cryptographic core is unbroken, that the victims were careless, and that the technology remains sound. That reading is true โ€” and also missing the point. On the other side, the Wall Street crowd will seize on the event as proof that self-custody is too dangerous for ordinary people, that regulated custodians are the only rational home for institutional capital. That reading is self-serving, and equally blind to the systemic lesson. The actual lesson is less comfortable for everyone: in a world where attackers can identify your wallet type from your chain behavior, your security infrastructure itself becomes an attack surface. The next evolution of self-custody security is not a better secure element. It is metadata discipline. It is address obfuscation. It is treating every transaction as an intelligence operation. It is asking, at every step, "Is this behavior making me visible?" There is a regulatory dimension here that should not be ignored. Large-scale thefts from self-custody setups have historically been used as ammunition by policymakers who argue that non-custodial wallets are too dangerous for ordinary consumers. The 1,367 BTC event gives that argument a fresh data point. We should expect renewed pressure for travel-rule extensions, wallet screening obligations, and even more aggressive measures aimed at "protecting" users from themselves. The irony is exquisite: a forensic report designed to alert the community to risk may end up being the regulatory wedge that pushes the industry closer to the very centralization that self-custody was supposed to escape. What should the community watch for in the aftermath? First, the destination addresses. The blockchain is a public ledger; if the victims' addresses are made public, the entire world becomes an investigator. Watch for the 1,367 BTC to move. If they hit an exchange, that is a potential sell-pressure event. If they sit dormant, the attacker is likely a cold-storage treasure hoarder with long time horizons โ€” which makes recovery less likely but also less immediate of a market concern. Second, the response from Coinkite. The quality and speed of the company's response is a signal. A transparent, technical, detailed statement will restore more confidence than a vague PR notice. Silence, on the other hand, will be read as the worst possible admission. Third, the response from the multi-sig services โ€” Unchained, Casa, and the rest. If they rapidly issue guidance clarifying whether their Coldcard-based multi-sig offerings were affected, that tells you whether the attack was a single-device problem or a systemic one. Their messaging will be the most honest evidence of how deep the damage runs. Fourth, the legal signal. If the victims identify themselves and hire forensic experts, we will see the full attack anatomy. The criminal-justice dimension matters: a theft of this magnitude will trigger federal law enforcement involvement in multiple jurisdictions, and any sanctions-related connections โ€” particularly to North Korean state-sponsored hacking groups with a history of high-value crypto thefts โ€” would escalate the matter to a geopolitical level. So what do we do with 1,367 BTC of increasingly urgent questions? The most productive move is to watch the next 72 hours to two weeks like a hawk. The information trail after an announcement of this scale is a luxury: Galaxy Research has to decide whether to publish the full report with transaction hashes and addresses, Coinkite has to decide whether to issue a statement, and the market has to decide whether it can see the difference between a Coldcard bug and a Coldcard-attribution event. Watch the destination addresses. Watch for those 1,367 BTC to move to exchanges. Watch whether the victims were multi-sig or single-sig, whether they were in the United States or in jurisdictions with different regulatory frameworks. And most of all, watch whether the hardware wallet community responds to this with a posture of denial or a posture of evolution. We did not see the targeting layer coming, and neither did the victims. The only question that matters now โ€” one that is not asking whether the cryptography held, but whether the community can accept a threat model that includes its own visibility on-chain โ€” will be answered over the next few months. If the answer is yes, the hardware wallet will evolve from a simple vault into a full counter-surveillance suite. If the answer is no, the attacks will keep coming. Because the data is clear: it is not the vault that gets broken. It is the knowledge of where the vault is. And in the age of on-chain intelligence, everyone's vault has a lighthouse on the roof.

Market Prices

BTC Bitcoin
$79,605.1 -1.76%
ETH Ethereum
$2,454.25 -2.78%
SOL Solana
$102.53 -1.36%
BNB BNB Chain
$747.7 +3.80%
XRP XRP Ledger
$1.4 -2.92%
DOGE Dogecoin
$0.0859 -1.89%
ADA Cardano
$0.2131 -3.49%
AVAX Avalanche
$7.5 +0.03%
DOT Polkadot
$0.9074 +3.64%
LINK Chainlink
$11.77 -2.05%

Fear & Greed

73

Greed

Market Sentiment

Event Calendar

{{ๅนดไปฝ}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Market Cap

All โ†’
1
Bitcoin
BTC
$79,605.1
1
Ethereum
ETH
$2,454.25
1
Solana
SOL
$102.53
1
BNB Chain
BNB
$747.7
1
XRP Ledger
XRP
$1.4
1
Dogecoin
DOGE
$0.0859
1
Cardano
ADA
$0.2131
1
Avalanche
AVAX
$7.5
1
Polkadot
DOT
$0.9074
1
Chainlink
LINK
$11.77

Tools

All โ†’

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

๐Ÿ‹ Whale Tracker

๐ŸŸข
0x1d25...e3f4
12m ago
In
873,376 USDT
๐ŸŸข
0x3892...487a
3h ago
In
4,047,556 USDT
๐Ÿ”ต
0xf237...110d
3h ago
Stake
4,448,541 USDC

๐Ÿ’ก Smart Money

0x0eb6...9fb5
Early Investor
+$4.3M
62%
0x57f8...0f9a
Arbitrage Bot
+$2.3M
83%
0xb136...4915
Top DeFi Miner
-$0.7M
87%