Bitcoin Faces $130 Million Coldcard Breach as Galaxy Research Chief Says Network Will Survive

Image: Kucoin
Main Takeaway
An estimated $130 million in Bitcoin was drained from Coldcard wallets, while Galaxy Digital’s Alex Thorn said the incident won’t threaten Bitcoin’s network.
Jump to Key PointsSummary
The breach and its scale
An estimated $130 million in Bitcoin was drained from about 7,300 addresses tied to Coinkite’s Coldcard hardware wallets, triggering concern across the cryptocurrency industry. The incident centers on devices marketed as “cold” wallets, which store private keys offline and are designed to reduce exposure to online attacks.
Alex Thorn, Galaxy Digital’s head of firmwide research, discussed the breach on Bloomberg Crypto and said Bitcoin itself will survive the incident. The available accounts connect the broad theft to a specific Coldcard-related compromise, while a separate account describes one victim who lost 17 BTC from a wallet that held about 30 BTC.
Why Bitcoin remains intact
The breach affects wallet security and custody practices, not Bitcoin’s underlying transaction network. Bitcoin’s blockchain records transfers through its consensus system, while Coldcard devices generate or protect the keys used to authorize those transfers. A compromise of devices or related software therefore creates losses for individual holders without rewriting the ledger or invalidating unrelated balances.
Thorn’s assessment separates the resilience of the protocol from the security of products built around it. Bloomberg’s interview framed the event as a serious shock for users and the crypto community, while the KuCoin account focused on the movement of stolen funds after one attack. Together, the accounts point to a containment problem around wallet infrastructure rather than a failure of Bitcoin’s core design.
Stolen funds move through crypto markets
In the individual case described by KuCoin, the attacker exchanged 17 BTC for Ether through THORChain before depositing the assets into Duel. The victim and associated researchers sent transaction hashes, fund-flow details and deposit information to Duel through its known contact channels, seeking a freeze.
Duel reportedly required the victim to contact law enforcement before taking action, despite claims that it follows know-your-customer and anti-money-laundering policies. Thorn warned that the platform could face significant legal action and said Duel knew the funds’ origin within minutes of notification. The account does not establish the final disposition of the assets or whether a freeze occurred.
Custody risks come into focus
The Coldcard incident puts renewed pressure on hardware-wallet makers, exchanges and decentralized trading infrastructure to explain where security controls failed and how quickly stolen assets can be tracked. A device described as offline still depends on secure initialization, firmware, transaction signing and user procedures. A weakness at any point can expose funds even when coins never sit on a conventional exchange.
The reported scale also raises questions for holders who treat hardware custody as a complete security solution. Users face practical decisions around firmware updates, backup storage, transaction verification and splitting large balances across wallets. Service providers face a different challenge: responding to clear evidence of theft without turning emergency freezes into arbitrary restrictions on legitimate users.
What happens next
The next phase will center on forensic analysis, asset tracing and accountability among the companies connected to the stolen funds. Investigators will need to establish how the Coldcard addresses were compromised, whether the affected wallets share a technical feature, and whether additional users remain exposed.
Duel’s response will also shape debate over compliance duties for crypto platforms handling assets identified as stolen. Thorn’s warning raises the stakes, but the published account provides no resolution to the dispute. For Bitcoin holders, the immediate lesson is narrower than a verdict on the cryptocurrency itself: the network can continue operating while weaknesses in wallet products and recovery processes impose substantial losses on users.
Key Points
Coldcard wallets suffered an estimated $130 million Bitcoin breach affecting roughly 7,300 addresses.
Alex Thorn said Bitcoin’s core network will survive the Coldcard wallet security incident.
One victim’s stolen 17 BTC moved through THORChain into Ether before reaching Duel.
Duel reportedly requested law-enforcement involvement before considering action on identified stolen funds.
The breach highlights security gaps between Bitcoin’s protocol and hardware-wallet custody products.
Questions Answered
The Coldcard Bitcoin hack drained an estimated $130 million from about 7,300 wallet addresses. The incident involved Coinkite hardware wallets and has raised questions about device and custody security.
Alex Thorn says Bitcoin will survive because the breach targets wallet security rather than the blockchain’s consensus network. Stolen private keys or compromised devices can cause user losses without disrupting Bitcoin’s ledger.
The stolen Coldcard Bitcoin in one reported case was exchanged for Ether through THORChain and deposited into Duel. The victim and researchers provided transaction records while requesting that Duel freeze the funds.
The published account does not state that Duel froze the stolen Coldcard funds. Duel reportedly asked the victim to contact law enforcement before taking action.
Bitcoin holders should treat hardware wallets as one part of a broader security process. Firmware practices, transaction verification, backups and distributing large balances across wallets remain important safeguards.
Source Reliability
50% of sources are highly trusted · Avg reliability: 67
Go deeper with Organic Intel
Simple AI systems for your life, work, and business. Each one includes copyable prompts, guides, and downloadable resources.
Explore Systems