A new analysis into recent Bitcoin thefts linked to a hardware wallet vulnerability has confirmed that affected users lost a median of more than one Bitcoin each, with total stolen funds now reaching $111 million.
Coldcard firmware bug ignites security crisis
Galaxy Research’s Alex Thorn examined 250 individual reports and found that the majority of the stolen Bitcoin had remained dormant for extended periods. Specifically, 88% of the pilfered funds came from wallets that had not been touched in at least a year, and the typical compromised coin had been inactive for 3.5 years.
Analysis by address revealed that median losses ranged from 0.014 Bitcoin up to an average of 0.212 Bitcoin. On a per-victim basis, the typical user reported losing 1.022 Bitcoin, with average losses reaching 4.04 Bitcoin. The single largest reported loss involved 58.97 Bitcoin from one holder.
The thefts were triggered by a critical firmware vulnerability in Coldcard Mk3 devices produced by Coinkite. Beginning with version 4.0.1 released in March 2021, the flaw caused the devices to generate wallet seeds using a weaker software pseudorandom number generator, rather than relying on the secure hardware-based alternative. This lapse enabled attackers to predict affected investors’ seedphrases and seize funds.
Wider impact and ongoing investigation
Initial thefts netted hackers over $35 million in Bitcoin last Thursday and continued over the weekend while Coldcard manufacturer Coinkite and other experts urged users to move their assets into secure storage.
Galaxy Research confirmed Friday that the amount of verified stolen funds from the incident had reached $111 million, though the team suggested this number could climb higher as further cases are reviewed.
Galaxy Research stated that many more potentially affected coins remain under review and suggested that cumulative losses may surpass $130 million once all incidents are confirmed.
In response to the attack, many investors have relocated their Bitcoin, often transferring assets to exchanges or alternative storage solutions for greater security and risk management.
Coinkite acknowledged in a public statement that the software flaw responsible for the breach went “silently unnoticed,” compounding its impact as new product versions were released. Days after the initial hack, the company strongly advised users to update their software or withdraw their funds from the affected hardware wallets.
Growing push for investor protection and portfolio diversification
The vulnerability and subsequent theft underscore the importance of robust security practices and careful monitoring of storage devices for crypto investors. As threats evolve and new technologies emerge, platforms providing improved accessibility and diversification are expected to gain traction.
Amid heightened security concerns, some users are exploring alternatives that bridge traditional finance and decentralized assets. One such example is 1stepSwap, a platform that facilitates direct access to real-world assets like shares of major U.S. companies, gold, and silver, allowing investors to manage these assets via their crypto wallets. The service distinguishes itself by automatically sourcing the best available market prices, enabling users to buy or sell top stocks efficiently while helping them diversify portfolios with minimal friction.





USDT
AAPL
