Three waves. One hundred million dollars. Zero technical details.
That is the complete public record on the Coldcard compromise, as disclosed by Galaxy Research. Three confirmed attack waves against hardware wallets, over $100 million in bitcoin stolen, and one detail buried beneath the headline: 90 percent of the stolen funds have not moved.
The consensus reading is comforting. The attackers have not cashed out. There is still a window for tracing, freezing, recovering.
That reading is a delay, not a diagnosis.
An attacker who executes three waves and then pauses is not stalling. They are staging. Either they are waiting for surveillance noise to settle before building laundering rails, or they are still inside the pipeline, identifying more victims. The fourth wave Galaxy suspects — the one that would push total losses past $130 million — is not speculative noise. It is the expected next interval in a series.
The code was solid. The logic was not.
Coldcard occupies a peculiar position in the security stack. It is the hardware wallet for the maximalist — the user who verifies firmware hashes on an air-gapped computer, checks authenticity holograms, and treats seed phrase exposure as a personal extinction event. The brand's marketing is deliberately anti-marketing: no screens, no Bluetooth, no concessions to convenience.
That user base is precisely why this attack matters. The victims were not broad retail users who drifted into a phishing page. They were the most security-conscious cohort in the ecosystem. If they can be hit in waves, the vulnerability sits in a layer most users never inspect: the path between manufacturing and the mailbox.
Galaxy Research's report is thin on mechanism but firm on scale. $100 million confirmed. Approximately 1,667 BTC. Three waves confirmed. A fourth suspected. Galaxy holds Tier 1 standing in industry research; its disclosures have historically been conservative rather than speculative. That makes the four-wave inference worth taking seriously, not dismissing.
The historical record offers no direct comparison. Ledger's 2020 incident was a marketing database leak — personal information exposed, not funds misappropriated. Trezor's extraction research in 2021 required physical device access and was never weaponized at scale. Both were single-point events. Both look like slivers against today's disclosure.
Hardware wallets became the industry's standard answer to exchange collapses. After Mt. Gox, after FTX, “not your keys, not your coins” converged into a silicon form factor. Coldcard specifically marketed itself as the paranoid-grade solution for bitcoin holders demanding control. Extracting $100 million from that trust anchor does not merely bruise one brand. It challenges the assumption that private keys held in offline silicon are unreachable by adversaries.
There is a dark irony in Coldcard's positioning. The brand sells security as a function of disconnection: your keys never touch a network, so they cannot be reached. That model protects against remote attackers. It does not protect against an adversary who touches the device before you do. The hardware wallet's core promise — that offline keys are unreachable — remains true at the silicon level. The promise breaks at the trust level, where any device arriving by mail is already an assumption.
The technical layer — how the attackers actually did it — remains opaque. And the opacity is itself a finding.
Let me work through the plausible mechanisms, ranked by fit to the observed pattern.
Supply chain interception places first. The distance between Coldcard's production line and the user's hands contains multiple uncontrolled handoffs: factory, logistics provider, warehousing agent, retail distributor. An attacker who intercepts a batch and replaces a secure element, or flashes tampered firmware at any point in that chain, gains control of every device in that batch. The multi-wave pattern fits this vector better than any other. Each new production batch is another opportunity to compromise. Confidence: medium. The pattern matches the data; the technical detail remains unconfirmed.
Firmware or update chain compromise follows. Coldcard signs its firmware releases. Breaking the signing chain permits mass injection of malicious code to every device that syncs. This is the highest-impact vector in theory and the least plausible in practice: a compromised signing server would trigger red flags across the security research community within hours. Three waves of quiet persistence imply someone who can operate without tripping alarms. Confidence: low-to-medium.
Physical side-channel extraction ranks next. Chip-level attacks like voltage glitching and electromagnetic emission analysis receive outsized attention at security conferences. They are also expensive, require direct device access, and do not scale to hundreds of victims. The cost structure of side-channel work suits targeting one high-net-worth individual, not three waves of batch victims. Confidence: low. The attacker's economics argue against this vector.
User-side seed phrase compromise closes the list. Phishing remains the largest attack category in bitcoin custody. But user-side compromise fails to explain the concentration pattern. Three distinct waves imply organized targeting, not opportunism. Confidence: low.
The most probable answer blends vectors one and two: an attacker with early access to the trust chain, exercising that access over time.
Now the number the market is ignoring.
Ninety percent of stolen bitcoin — roughly $90 million in value — has not moved. Coverage reads this as preservation. It is not. It is inventory.
An attacker who liquidates immediately converts assets into traceable events. The blockchain is permanent; every sat attributable to the theft becomes marked territory forever. Moving funds through chain-hopping services, mixers, or privacy protocols takes planning. The pause between exfiltrating a third wave and consolidating funds is the operational span of an attacker planning to convert the full balance. It is not the pause of an attacker who cannot.
I have seen this shape before. During the 2020 DeFi summer, I spent six weeks reverse-engineering Compound Finance's interest rate model. The visible code compiled clean; the liquidation thresholds were mathematically brittle during volatility spikes. The market monitored the interest rate curves — which behaved as modeled — while the failure mode sat in an assumption about input behavior. The flat line in the logs was the signal, not the noise.
A flat line is more dangerous than a spike.
Same structure, different layer. The hardware wallets functioned as designed. Users did not lose seed phrases to phishing pages. The fault lives in the layer between manufacture and use: logistics, distribution, firmware delivery. None of that is visible to the end user verifying a device's authenticity hologram.
The 90 percent figure also carries operational meaning for the exchange layer. Roughly $90 million in identifiable bitcoin sits in addresses that chain surveillance firms will have flagged. If those funds move to a regulated exchange, the KYC layer converts an anonymous theft into a traced movement. That is the strongest counter-pressure available to the industry — and it only holds while the funds remain stationary. Every day the attacker waits buys the tracing ecosystem time to map the path.
And then there is the silence. No vendor security bulletin. No notification framework for potentially affected users. No indicators of compromise published. The disclosure cadence is lagging the attack cadence, and that gap is precisely where the next wave lives.
Silence in the logs speaks louder than bugs.
Now the inconvenient counter-argument, because the panic narrative is not fully honest either.
This was not a cryptographic break. No algorithm was compromised. No consensus rule was violated. The bitcoin network processed every transaction as designed. The attack operated in the physical layer — the chain between device manufacture and user possession — which is a fundamentally different threat model from a smart contract exploit or protocol-level flaw.
Cold storage remains the correct mechanism for long-term bitcoin custody. A bank vault does not protect against a compromised armored truck, but that is not an argument against vaults; it is an argument for auditing logistics. The same logic applies here. Users who verify device provenance, check firmware signatures, and source hardware from official channels still hold a security profile that outperforms custodial alternatives.
The monetary impact is contained. The stolen bitcoin — roughly 1,667 BTC — has not left the supply. These coins will eventually move, and if they hit regulated exchanges in volume, the addresses can be frozen and the liquidity shock limited. Bitcoin's total supply is unchanged. The protocol is not impaired.
The market's actual adjustment will occur in how self-custody is assembled. Multisig wallets, MPC-based custody, and verified supply chain sourcing will gain share. That is a healthy correction, not a collapse.
Check the inputs, ignore the hype.
The next 90 days determine whether this becomes a Coldcard-specific crisis or an industry-wide reckoning. If the fourth wave confirms, the issue is systemic: the hardware wallet category requires supply chain validation standards, not just code audits. If the funds begin moving, the tracing ecosystem faces the test of whether on-chain surveillance can intercept an attacker who has had months to plan.
The lesson is not that hardware wallets are broken. The lesson is that single-point trust is a risk vector, regardless of whether that trust sits in an exchange, a smart contract, or a factory floor on another continent.
The ecosystem is migrating toward multisig, MPC, and verified sourcing. The question is whether that migration completes before the fifth wave arrives.