


TechFlame News: Galaxy Research head Alex Thorn said on X that attacks exploiting the Coldcard hardware wallet vulnerability have clearly slowed, but cumulative losses are still climbing as more victims come forward. The incident has hit the Bitcoin community hard, since the victims are primarily long-term BTC holders who adhered to the philosophy of self-custody cold storage—not users who lost funds through high-risk trading or DeFi activity.
At $112 million, the incident now ranks among the top 20 largest hacks in crypto history, and it stands as one of the most severe security breaches ever in the self-custody hardware wallet space. Bitcoin culture may be entering a new phase as a result: the old approach of relying purely on ideological evangelism and extreme self-custody rhetoric is coming to an end. The community needs to place greater emphasis on technical security, lower the barrier to entry for users, and stop shifting the burden of security onto ordinary individuals. This crisis could ultimately push the Bitcoin ecosystem toward a more mature security framework.
Galaxy Research has so far directly contacted 190 victims and has confirmed with high confidence that the exploit has resulted in the theft of 1,778.84 BTC (approximately $112.7 million) across more than 8,600 addresses. This tally does not yet include medium-confidence suspicious attack records, such as the unconfirmed "Wave 4." If those potential attack vectors are included, total losses could expand to 2,417.35 BTC (approximately $153 million).
Meanwhile, the incident is reshaping market perceptions of self-custody security. Galaxy notes that multisig wallets have emerged as the "winners" of this event—so far, not a single stolen transaction has come from a multisig wallet. Multisig service providers including Casa, Unchained, Nunchuk, and Anchorwatch have all observed a notable uptick in user sign-ups and BTC inflows.