What happened
Galaxy Digital's research team released a technical analysis Thursday of the Coldcard hardware wallet exploit, per CryptoBriefing, pegging cumulative losses above $111 million across a batch of affected devices. The firm's writeup describes a firmware-level compromise: attackers were able to push or coerce a modified firmware image onto targeted units, which then signed outbound transactions the user did not authorize.
This is not a seed phrase leak. It's a signing-integrity failure. That distinction matters, because Coldcard's entire pitch, air-gapped signing with PSBT files shuttled via microSD, is built on the assumption that a device that never touches the internet cannot be silently reprogrammed.
Galaxy's timeline traces the first confirmed drains to earlier this week, with the loss figure climbing as forensic analysts tag more compromised addresses. Coinkite, the Canadian firm behind Coldcard, had not published a firmware advisory or a confirmed patched build at the time of Galaxy's writeup.
Why it matters
Hardware wallets are the load-bearing wall of self-custody, and Coldcard sits near the top of the trust stack for Bitcoin-only holders and treasury-scale custodians. A $111 million loss traced to firmware, not user error, is the exact scenario the category was engineered to prevent. Galaxy's analysis pushes the conversation past the usual 'user got phished' framing that follows most wallet incidents.
If the exploit reproduces on other vendors that share supply-chain components or update paths, the blast radius extends well past Coinkite. The headline looks contained to one vendor. The threat model doesn't.
