Galaxy Digital said it has confirmed at least 15 attackers exploited a Coldcard vulnerability.
Cointelegraph reported on Monday that Alex Thorne (알렉스 손), head of research at Galaxy Digital, said the company identified additional attackers that had not previously been revealed, based on newly filed victim reports after the incident.
Thorne said the attack differed from centralized exchange hacks because new attackers could only be confirmed through victim reports.
He said a report from a victim who had less than 1 bitcoin stolen led to the discovery of a new attack in which 12 bitcoin was drained from 126 addresses.
The scale of losses is also growing. Galaxy Research estimated losses from three confirmed attacks at $100 million. It said total losses could rise to about $130 million in bitcoin when a suspected fourth attack is included.
The incident is fueling an intensifying debate over cold storage wallet security. Dragonfly managing partner Haseeb Qureshi (하십 쿠레시) claimed some AI models re-discovered the vulnerability in under 20 minutes and said it could have been prevented with about $2 worth of AI hardening.
Thassaphat Saerejitthima (탓사팟 새레짓티마), head of data at crypto analysis platform Tokonomist, said it was unlikely that an AI model independently found the vulnerability before it was disclosed.
Francesco (프란체스코), co-founder of crypto research firm Castle Labs, said Coldcard private keys may have been affected by the vulnerability. He said Coldcard used private-key entropy of about 40 bits, far lower than standard wallets, due to a firmware bug, making attacks easier compared with the 128-bit standard of a 12-word seed.