Galaxy: At least 15 attackers exploited Coldcard vulnerability
NEW YORK, Aug. 4. Galaxy said at least 15 separate attackers exploited a vulnerability in Coldcard. Dragonfly's managing partner characterized the exposure as one that $2 worth of AI hardening could have prevented.
Key takeaways
- Galaxy said at least 15 separate attackers exploited a vulnerability in Coldcard.
- Dragonfly's managing partner said the vulnerability could have been prevented with roughly $2 worth of AI hardening.
- Galaxy did not disclose cumulative losses, attacker identities, or the technical mechanism of the flaw in the cited materials.
- The 'at least' phrasing means the final number of attackers could be higher than 15.
- Coldcard's response to the characterization was not included in the reported materials.
NEW YORK, Aug. 4. Galaxy said at least 15 separate attackers exploited a vulnerability in Coldcard. Dragonfly's managing partner characterized the exposure as one that $2 worth of AI hardening could have prevented.
Scope of exploitation
Fifteen distinct threat actors is the floor count Galaxy reported. The firm's phrasing, "at least," leaves open the possibility of a higher final number. Galaxy did not disclose cumulative losses, attacker identities, or the technical mechanism of the flaw in the materials cited.
The cost-of-prevention argument
Dragonfly's managing partner offered the starkest framing of the incident. The partner said the vulnerability was avoidable for roughly $2 applied to AI hardening. That places the episode in a failure-of-prevention category rather than a novel or unforeseeable attack. Coldcard's response to the characterization was not included in the reported materials.