Coldcard exploit losses have affected Canadian Bitcoin holders most heavily among tracked regions. Chainalysis estimates that about 25% of attributed losses belong to owners in Canada.
The analytics firm linked affected addresses to likely regions using on-chain records and exchange connections. It said Coldcard gained local adoption through influencer campaigns and Canada’s early Bitcoin culture.
The United States and Thailand also recorded significant losses during this week’s attacks. Estimates place the value of stolen Bitcoin between $110 million and $150 million.
Coldcard Exploit Prompts Wider Security Response
The incident has triggered a coordinated effort to identify similar weaknesses across Bitcoin software. A group called the Red Team is conducting AI-assisted audits of wallets, libraries, tools, and infrastructure.
Rob Hamilton, chief executive of AnchorWatch, is leading the initiative. The team has spent more than $20,000 on model tokens and secured further funding.
So far, the Red Team has scanned 150 code repositories and contacted relevant project teams. It has also approached OpenAI about using Cyber Harness for deeper vulnerability testing.
Researchers have used the free Kimi K3 model to examine cryptocurrency codebases. The audits highlight how cheaper models can support both defensive research and malicious discovery.
The Red Team says its reviews are finding about one serious or critical vulnerability each hour. Its testing systems have reached several Bitcoin projects within the past 12 hours.
Multiple Attackers Target Exposed Wallets
On-chain evidence indicates that the Coldcard theft involved several entities rather than one attacker. Alex Thorn, head of Firmwide Research, said the activity occurred in multiple waves.
The first wave caused the largest losses. Onchain Lens reported that attackers removed more than 1,816 BTC from 5,200 affected addresses.
Most stolen funds remain in destination wallets. This differs from many cryptocurrency attacks, where criminals move assets through mixers within hours.
One wallet holding about 64 stolen BTC appears to have started early mixing activity. It mixed 10 BTC and transferred the remaining 54 BTC elsewhere.
Law enforcement agencies have tagged most destination addresses. However, mixing services can make portions of the funds harder to trace and recover.
Owners Urged to Replace Wallet Seeds
Coldcard users have received advice to do more than install firmware updates. Security guidance recommends creating a new wallet seed and moving funds immediately.
Users have also been urged to apply higher transaction fees. In some cases, owners recovered funds by outbidding and front-running pending attacker transactions.
The exploit has affected broader Bitcoin sentiment and renewed concerns about self-custody risks. It also shows how quickly multiple attackers can exploit publicly known weaknesses.
The Red Team’s work aims to reduce similar incidents by auditing critical components before attackers locate flaws. Its current campaign covers software used throughout the Bitcoin ecosystem.
The post Coldcard Exploit Hits Canadian Bitcoin Holders Hardest as Losses Reach 1,816 BTC first appeared on Coinfea.
