Coldcard Exploit: 87% of Stolen Bitcoin Still Unmoved After $114 Million Attack
Key Takeaways
- •Galaxy Research attributes 1,789.28 BTC to the Coldcard exploit, valued at roughly $114.7 million at the time of theft.
- •Investigators say 1,561 BTC, or 87.3% of the stolen funds, has not yet been moved.
- •The attack exploited a 2021 Coldcard firmware flaw that weakened randomness during seed generation inside the device.
- •The vulnerability mainly affected certain single-signature wallets and did not require physical access to users’ devices.
- •Some later theft proceeds have already been routed through CoinJoin and peel-chain transactions to make tracing harder.

Most of the Bitcoin stolen in a major Coldcard hardware wallet exploit remains untouched, even as blockchain researchers continue to trace the funds. Galaxy Research now attributes 1,789.28 BTC to the attack, worth roughly $114.7 million at the time of the theft.
The latest estimate spans 8,865 affected addresses. Researchers determined that attackers have not moved 1,561 BTC — 87.3% of the stolen funds. That Bitcoin remains in addresses believed to be controlled by the attackers, including the proceeds from the first three theft waves.
The vulnerability behind the theft
The attack exploited a flaw in Coldcard firmware dating back to 2021. Coldcard, a Bitcoin-only hardware wallet made by Coinkite, is widely used by self-custody holders, and the case stands out because the compromise occurred at the seed-generation stage inside the device rather than through user error such as phishing. The defect weakened the randomness — the entropy — used to generate certain wallet seeds, the master secrets from which a wallet's private keys are derived. That allowed attackers to reconstruct vulnerable private keys without ever physically accessing users' devices, breaking the assumption that keys generated and held offline are beyond an attacker's reach.
The first major sweep began on July 30 and drained more than 1,000 BTC from affected wallets within minutes. Additional waves followed, pushing estimated losses above $100 million.
According to security researchers, the vulnerability primarily affected certain single-signature wallets — those controlled by one key rather than a multi-signature setup. Coldcard urged affected users to generate new seeds and move their Bitcoin, noting that simply updating the firmware does not repair a wallet that has already been compromised.
Tracking the stolen Bitcoin
While most of the stolen Bitcoin remains stationary, attackers have started moving portions of the funds. Galaxy reported that some Bitcoin from later waves passed through CoinJoin transactions — collaborative transactions that pool many users' coins to obscure which inputs belong to whom — as well as peel chains, where funds are split off in successive transfers to complicate tracing, and other techniques designed to make following the money harder.
Galaxy's updated assessment also draws on 221 victim reports covering 790.72 BTC. The median reported loss was 1.04272 BTC, meaning more than half of those reports involved losses exceeding 1 BTC.
Researchers have shared the identified attacker addresses with cryptocurrency exchanges, compliance firms, and law enforcement agencies, with the goal of helping to identify and potentially freeze the funds if they eventually reach centralized platforms. Past cases show how long that can take — and how consequential it can be: funds stolen in the 2016 Bitfinex hack, roughly 120,000 BTC, remained largely untouched for more than five years before U.S. authorities seized the bulk of the haul in 2022.
For now, the large volume of unmoved Bitcoin gives investigators a valuable opportunity to monitor the blockchain. However, the funds could become harder to trace if the attackers accelerate their laundering efforts.