Galaxy said at least 15 different attackers exploited a vulnerability tied to Coldcard, according to source material from Cointelegraph. The report also cited Dragonfly’s managing partner as saying the weakness may have been avoided with about $2 worth of AI hardening.
The development matters because hardware wallet security is a core trust issue for crypto users and companies. When a vulnerability is reportedly exploited by multiple attackers, it highlights how even narrow technical weaknesses can become a wider ecosystem concern.
The source material does not provide details on the amount of funds affected, the timing of the attacks, or the specific technical mechanism involved. It also does not state whether Coldcard users need to take any particular action.
For readers, the key takeaway is that Galaxy identified repeated exploitation of the Coldcard vulnerability, while the Dragonfly comment frames the incident as a potentially preventable security failure. The case adds to ongoing scrutiny of how crypto infrastructure providers test and harden products before attackers find weaknesses first.