Updated Aug 4, 2026
/Bezos Plans $4 Billion Amazon Stock Sale After Recent Price Surge/Galaxy: At least 15 attackers exploited Coldcard vulnerability/Chatham Lodging AFFO per share rises 22% in Q2 2026 as RevPAR hits all-time high/Millrose Properties posts $0.76 GAAP EPS, revenue falls short at $196.9 million/Trump releases declassified election intelligence, cites 'shocking vulnerabilities' and alleged Chinese voter data scheme/Star Wars: The Mandalorian and Grogu moves to digital streaming after box office stall/Bezos Plans $4 Billion Amazon Stock Sale After Recent Price Surge/Galaxy: At least 15 attackers exploited Coldcard vulnerability/Chatham Lodging AFFO per share rises 22% in Q2 2026 as RevPAR hits all-time high/Millrose Properties posts $0.76 GAAP EPS, revenue falls short at $196.9 million/Trump releases declassified election intelligence, cites 'shocking vulnerabilities' and alleged Chinese voter data scheme/Star Wars: The Mandalorian and Grogu moves to digital streaming after box office stall

Galaxy: At least 15 attackers exploited Coldcard vulnerability

NEW YORK, Aug. 4. Galaxy said at least 15 separate attackers exploited a vulnerability in Coldcard. Dragonfly's managing partner characterized the exposure as one that $2 worth of AI hardening could have prevented.

By Sofia Almeida2 min read
Share

Key takeaways

  • Galaxy said at least 15 separate attackers exploited a vulnerability in Coldcard.
  • Dragonfly's managing partner said the vulnerability could have been prevented with roughly $2 worth of AI hardening.
  • Galaxy did not disclose cumulative losses, attacker identities, or the technical mechanism of the flaw in the cited materials.
  • The 'at least' phrasing means the final number of attackers could be higher than 15.
  • Coldcard's response to the characterization was not included in the reported materials.

NEW YORK, Aug. 4. Galaxy said at least 15 separate attackers exploited a vulnerability in Coldcard. Dragonfly's managing partner characterized the exposure as one that $2 worth of AI hardening could have prevented.

Scope of exploitation

Fifteen distinct threat actors is the floor count Galaxy reported. The firm's phrasing, "at least," leaves open the possibility of a higher final number. Galaxy did not disclose cumulative losses, attacker identities, or the technical mechanism of the flaw in the materials cited.

The cost-of-prevention argument

Dragonfly's managing partner offered the starkest framing of the incident. The partner said the vulnerability was avoidable for roughly $2 applied to AI hardening. That places the episode in a failure-of-prevention category rather than a novel or unforeseeable attack. Coldcard's response to the characterization was not included in the reported materials.

Related reading

Frequently asked

How many attackers exploited the Coldcard vulnerability?

Galaxy reported at least 15 distinct threat actors, and its 'at least' phrasing leaves open the possibility of a higher final number.

How much would it have cost to prevent the vulnerability?

Dragonfly's managing partner said the flaw was avoidable for roughly $2 applied to AI hardening.

Did Galaxy reveal how much money was lost or how the flaw worked?

No; Galaxy did not disclose cumulative losses, attacker identities, or the technical mechanism of the flaw in the cited materials.

Did Coldcard respond to the claims?

Coldcard's response to the characterization was not included in the reported materials.