- Galaxy Research reports approximately $88.6 million stolen from 4,585 Coldcard addresses across three waves of theft.
- The exploit, stemming from a March 2021 firmware flaw that caused weak seed phrase randomness, is ongoing and likely LLM-orchestrated.
- Every single-signature Coldcard address created after the vulnerable firmware version is expected to be drained eventually.
- Affected users are moving Bitcoin back to centralized exchanges, reversing the typical 'not your keys, not your coins' principle.