Galaxy has attributed roughly 40% of activity in Coldcard’s second hack wave to white-hat actors, according to a claim circulating from the digital asset firm.
Galaxy has attributed roughly 40% of activity in Coldcard’s second hack wave to white-hat actors, according to a claim circulating from the digital asset firm. The attribution, if confirmed, would mean a significant portion of the incident involved security researchers or ethical hackers rather than purely malicious parties, though the basis for that assessment has not been publicly detailed.
What Galaxy Said About Coldcard’s Second Hack Wave
Galaxy’s assessment places approximately 40% of the second wave of activity tied to the Coldcard incident in the white-hat category. White-hat actors in security contexts are typically individuals who probe or exploit vulnerabilities to expose them, sometimes without prior authorization from the affected party, with the intent of disclosure rather than theft. For related coverage, see Israel's Largest Bank Taps Galaxy for Bitcoin, Ether, Solana Trading.
WHAT TO KNOW
- Galaxy made the attribution linking roughly 40% of the second hack wave to white-hat activity.
- The claim concerns the second wave specifically, not the full scope of the Coldcard incident.
Coldcard is a Bitcoin hardware wallet manufactured by Coinkite, widely used among self-custody advocates for its air-gapped signing capabilities. The device’s user base skews toward Bitcoin holders who prioritize security, making any confirmed vulnerability particularly significant to that community. An earlier phase of the incident saw white hats recover 52.37 BTC in a Coldcard recovery operation, establishing a precedent for ethical-actor involvement in this incident. For related coverage, see ECB Says Stablecoin Deposit Rule Could Hurt EU Banks.
What the White-Hat Link Could Mean for the Incident
A connection to white-hat activity does not automatically establish that the relevant portion of the second wave was authorized, harmless, or coordinated with Coinkite in advance. Unauthorized access, even when motivated by disclosure, can still constitute a legal or security concern depending on jurisdiction and the methods used.
Galaxy’s assessment raises several questions that the available information does not answer: how the firm determined which activity was white-hat in nature, whether those actors have since communicated findings to Coinkite, and whether any funds moved during the second wave have been returned. Galaxy, which has expanded its institutional services including serving as a trading infrastructure partner for major banks, has not publicly released a methodology for this attribution as of this report.
The distinction between the first and second hack waves also remains unexplained in the available context. Whether the two waves represent separate exploit vectors, separate groups of actors, or sequential phases of the same attack is not established by Galaxy’s reported statement alone.
What Remains to Be Clarified
Several details would be necessary to fully evaluate Galaxy’s 40% attribution. These include the methodology used to distinguish white-hat from malicious activity, the scope of the estimate, whether the 40% refers to the number of transactions, the volume of funds involved, or the number of distinct actors, and the full timeline of the second wave.
No response from Coinkite or confirmation from identified white-hat researchers has been included in available reporting. The question of whether affected Coldcard users face any residual exposure, and what remediation steps have been taken or recommended, also remains open. Galaxy’s growing role in institutional Bitcoin infrastructure gives its security assessments weight in the industry, but that weight depends on the underlying methodology being made transparent.
For Bitcoin holders using hardware wallets, the incident underscores that even airgapped devices exist within a broader security ecosystem that includes firmware supply chains, physical access vectors, and the humans who interact with them. Until Coinkite or Galaxy publish a detailed post-mortem covering both hack waves, the full picture of what occurred and who was responsible remains incomplete.
Additional source references: source document 1, source document 2.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.