Updated Sep 2, 2026
/Trump and Rubio seal Venezuela oil deal covering 65 billion barrels across 17 fields/Bond rout gathers pace as borrowing costs hit multi-decade highs/Van Jones calls El-Sayed's total Israel arms embargo 'insane,' cites Obama legacy on defense/Memecoin buys on Robinhood Wallet and Fomo coded as "digital media," sidestepping card-network crypto rules/Caring Brands (CABR) Closes $4.6 Million Initial Series B Preferred Stock Private Placement/Sanmar Group takes majority stake in AltEons Energy to back 1.5GW India pipeline/Trump and Rubio seal Venezuela oil deal covering 65 billion barrels across 17 fields/Bond rout gathers pace as borrowing costs hit multi-decade highs/Van Jones calls El-Sayed's total Israel arms embargo 'insane,' cites Obama legacy on defense/Memecoin buys on Robinhood Wallet and Fomo coded as "digital media," sidestepping card-network crypto rules/Caring Brands (CABR) Closes $4.6 Million Initial Series B Preferred Stock Private Placement/Sanmar Group takes majority stake in AltEons Energy to back 1.5GW India pipeline

Galaxy: At least 15 attackers exploited Coldcard vulnerability

NEW YORK, Aug. 4. Galaxy said at least 15 separate attackers exploited a vulnerability in Coldcard. Dragonfly's managing partner characterized the exposure as one that $2 worth of AI hardening could have prevented.

By Julian Merrick2 min read
Share

Key takeaways

  • Galaxy said at least 15 separate attackers exploited a vulnerability in Coldcard.
  • Dragonfly's managing partner said the vulnerability could have been prevented with roughly $2 worth of AI hardening.
  • Galaxy did not disclose cumulative losses, attacker identities, or the technical mechanism of the flaw in the cited materials.
  • The 'at least' phrasing means the final number of attackers could be higher than 15.
  • Coldcard's response to the characterization was not included in the reported materials.

NEW YORK, Aug. 4. Galaxy said at least 15 separate attackers exploited a vulnerability in Coldcard. Dragonfly's managing partner characterized the exposure as one that $2 worth of AI hardening could have prevented.

Scope of exploitation

Fifteen distinct threat actors is the floor count Galaxy reported. The firm's phrasing, "at least," leaves open the possibility of a higher final number. Galaxy did not disclose cumulative losses, attacker identities, or the technical mechanism of the flaw in the materials cited.

The cost-of-prevention argument

Dragonfly's managing partner offered the starkest framing of the incident. The partner said the vulnerability was avoidable for roughly $2 applied to AI hardening. That places the episode in a failure-of-prevention category rather than a novel or unforeseeable attack. Coldcard's response to the characterization was not included in the reported materials.

Related reading

Frequently asked

How many attackers exploited the Coldcard vulnerability?

Galaxy reported at least 15 distinct threat actors, and its 'at least' phrasing leaves open the possibility of a higher final number.

How much would it have cost to prevent the vulnerability?

Dragonfly's managing partner said the flaw was avoidable for roughly $2 applied to AI hardening.

Did Galaxy reveal how much money was lost or how the flaw worked?

No; Galaxy did not disclose cumulative losses, attacker identities, or the technical mechanism of the flaw in the cited materials.

Did Coldcard respond to the claims?

Coldcard's response to the characterization was not included in the reported materials.