Blockchain forensic teams tracking the Coldcard hardware wallet exploit have yet to converge on a single loss figure, with current estimates spanning 12 to 40 bitcoin across victim submissions and automated clustering. CoinGecko data shows BTC trading at $64,181, down 1.2% in 24 hours, placing the potential haul between $770,000 and $2.6 million at current prices.
Coinkite disclosed that a firmware verification bypass allowed malicious transaction signing on devices shipped before March 2024. The flaw resided in the secure element's attestation check, which failed to validate a critical certificate field under specific nonce conditions. Researchers at Unciphered reproduced the exploit on a test device within 72 hours of the advisory, confirming remote signing capability without physical access.
Where the funds went
On-chain analysis from Arkham Intelligence and Chainalysis shows stolen bitcoin dispersing through at least 17 intermediate addresses before entering Wasabi and JoinMarket mixing pools. The largest single cluster — 8.4 bitcoin — moved to a Wasabi coordinator address on block 842,110. A second cluster of 5.1 bitcoin reached a JoinMarket yield generator two blocks later. Investigators note the mixing delay of roughly 14 hours suggests manual coordination rather than automated sweeping.
Response and recovery
Coinkite pushed firmware version 5.1.2 within 36 hours of detection, adding mandatory certificate pinning and nonce validation. The company has offered free device replacement for affected serial ranges. Exchange compliance teams at Kraken, Coinbase, and Bitstamp have frozen 3.2 bitcoin linked to the exploit clusters, representing the first verified recoveries. Negotiations with mixing service operators remain ongoing, though Wasabi's zkSNACKs coordinator has historically resisted seizure requests.
User impact and exposure
Approximately 14,000 devices fall within the vulnerable serial range, though Coinkite estimates active exploitation affected fewer than 200 users based on telemetry. The company has not disclosed whether the attacker gained access to its supply chain or developed the exploit independently. Affected users report unauthorized transactions ranging from 0.05 to 2.3 bitcoin per wallet.
The exploit architecture — targeting secure element attestation rather than the main MCU — mirrors the technique used in the 2023 Ledger Connect Kit compromise, where a malicious NPM package injected code into downstream dApps. Both attacks bypassed hardware isolation by exploiting trust assumptions in the software supply chain. Trezor and Foundation have since added independent attestation verification to their firmware review processes.
| Metric | Value | Source |
|---|---|---|
| Estimated loss range | 12–40 BTC | Victim reports + chain analysis |
| Verified frozen funds | 3.2 BTC | Exchange compliance teams |
|---|---|---|
| Vulnerable devices | ~14,000 | Coinkite telemetry |
| Active exploit victims | <200 | Coinkite estimate |
|---|---|---|
| Firmware patch deployed | v5.1.2 | Coinkite advisory |
| Mixing entry points | 2 (Wasabi, JoinMarket) | Arkham Intelligence |
The investigation continues to map the full flow path. The next critical milestone is the Wasabi coordinator's next output transaction, which may reveal whether mixed funds consolidate at a known exchange deposit address.