Losses from the Coldcard hardware wallet exploit have surged to over $130 million in bitcoin, affecting more than 7,300 addresses. That’s up sharply from the first major sweep reported just days ago, when about 1,082 bitcoin, then worth roughly $70 million, was drained from 1,196 wallets in just 41 minutes. What’s changed is not how the attack works, but how widespread it’s become. Galaxy Research now says at least 15 attackers have been identified exploiting the flaw, shifting the picture from a focused incident to an ongoing, multi-party compromise.

The root issue stems from a March 2021 firmware change affecting key generation on some Coldcard devices. Reporting says some devices could fall back to a predictable software mechanism, creating an opening for attackers to target vulnerable wallets. That means this is not a remote takeover of devices, but a firmware-level weakness with lasting consequences for anyone whose wallet was generated under those conditions.

This remains a failure in specific Coldcard firmware, not a breach of Bitcoin itself or all hardware wallets. Researchers continue tracing vulnerable addresses, and the key question now is whether the tally climbs further as more compromised wallets come to light.