Investigations into a long-standing vulnerability affecting Coldcard hardware wallets have revealed that at least 15 distinct attackers have exploited the security flaw, with cumulative stolen funds now estimated at approximately $130 million. The scale of the compromise became further apparent when Bitcoin worth close to $32 million moved for the first time in 12 years yesterday, suggesting that dormant accounts compromised through this exploit have begun transferring assets after more than a decade of inactivity.

Research conducted by Galaxy has identified at least 15 different attackers who have taken advantage of the vulnerability, indicating a widespread and prolonged exploitation campaign rather than an isolated incident perpetrated by a single entity. The involvement of multiple distinct threat actors suggests that knowledge of the security flaw circulated broadly within attacker communities, enabling various independent groups to develop and deploy exploits targeting vulnerable devices. This fragmentation of the attack vector complicates attribution efforts and indicates that the vulnerability was likely discovered and shared among different malicious actors over an extended timeframe.

The recent movement of approximately $32 million in Bitcoin marked the first time these specific funds had transferred in over 12 years, according to Bitcoin Magazine. This activity suggests that attackers who gained access to older, dormant wallets may finally be liquidating or relocating assets after years of inactivity, contributing to the growing tally of stolen funds now estimated at $130 million. The awakening of these long-dormant coins provides concrete evidence that compromised accounts from earlier periods remain vulnerable to exploitation and liquidation, potentially years after the initial security breach occurred.

Security analysts have emphasized the preventable nature of the vulnerability. According to Cointelegraph, Dragonfly’s managing partner indicated that the exploit may have been avoided with just $2 worth of AI hardening per device. This relatively insignificant investment stands in stark contrast to the substantial losses suffered by victims, now totaling approximately $130 million across the identified attack campaigns. The assessment raises significant concerns regarding security practices in hardware wallet manufacturing, particularly regarding the implementation of cost-effective preventive measures that could have averted large-scale theft affecting numerous cryptocurrency holders.

The identification of at least 15 separate attackers by Galaxy researchers underscores the systemic nature of the vulnerability and its attraction to multiple threat actors operating independently. As the total estimated damages reach $130 million, the recent movement of $32 million in previously dormant Bitcoin serves as a stark reminder that the consequences of hardware security flaws can manifest years after the initial compromise, with attackers patiently holding stolen assets before moving them to new locations.