Coldcard Bitcoin Theft Exceeds $75M as Galaxy Research Uncovers Second Attack Wave
Key Takeaways
- •The two attacks collectively compromised 2,673 addresses and stole 1,158.81 BTC valued at approximately $75.1 million, with no overlap in victim addresses between the two waves.
- •All stolen Bitcoin remains unspent across seven attacker-controlled wallets, and researchers flagged that any movement to exchanges or mixing services would signal the next major development.
- •Galaxy Research warned that its tracking approach relies on transaction fingerprints, meaning future attackers could potentially evade detection by modifying fee structures or spreading transfers over longer periods.
- •Single-signature Coldcard wallet users are urged to move funds to newly generated wallets immediately, whereas multisignature users remain protected as long as a single device cannot authorize transactions alone.
- •Binance founder Changpeng Zhao emphasized that firmware updates cannot remediate previously compromised wallet seeds, requiring users to manually migrate their affected funds.

Galaxy Research has identified a second wave of Bitcoin thefts linked to a Coldcard wallet vulnerability, bringing total losses to 1,158.81 BTC — approximately $75.1 million. Coldcard, a Bitcoin-only hardware wallet manufactured by Coinkite, is widely used among self-custody advocates for its air-gapped security design. The two coordinated attacks targeted 2,673 addresses between July 30 and July 31, and all stolen funds remain untouched across seven attacker-controlled wallets. Researchers warned that further attacks are still possible.
Second Wave Expands the Scope of the Attack
The first attack drained 1,082.65 BTC from 1,195 addresses in just 41 minutes on July 30. Roughly 27 hours later, a second operation siphoned an additional 76.16 BTC from 1,478 separate addresses over a period of three hours and 42 minutes.
Galaxy Research noted that the two victim groups shared no overlapping addresses. Although the second wave reached a larger number of wallets, it targeted considerably smaller balances than the initial campaign.
The two attacks also exhibited distinct transaction fee patterns. The first wave consistently used fees of 30 sat/vbyte, while the second wave primarily used 10 and 50 sat/vbyte, with several smaller transactions at approximately four sat/vbyte.
Researchers Track the Stolen Bitcoin
According to Galaxy Research, all 1,158.66 BTC remains unspent across seven attacker-controlled addresses. Researchers described the lack of movement as unusual for a theft of this magnitude, noting that any transfer into exchanges or mixing services would mark the next significant development.
The firm also reported that engineers at Block may have uncovered identifying information connected to the suspected attacker.
Galaxy Research explained that its tracking methodology relies on transaction fingerprints rather than the underlying vulnerability. Researchers cautioned that future attackers could evade similar detection by altering transaction fees, adding change outputs, using separate destination addresses, or distributing transfers over extended timeframes.
Security Advisories Persist
Galaxy Research urged all users with affected single-signature Coldcard-generated wallets to transfer their funds to newly generated wallets immediately. Multisignature users, however, remain protected as long as Coldcard devices alone are insufficient to authorize transactions.
Galaxy Head of Research Alex Thorn alleged that a hacker converted a portion of one victim's stolen Bitcoin into Ether via THORChain before depositing approximately 229.72 ETH into Duel Casino. Thorn said the victim and a researcher requested a freeze, but the platform advised them to contact law enforcement.
Separately, Binance founder Changpeng Zhao, commonly known as CZ, stated that firmware updates cannot safeguard previously generated self-custody wallets. He emphasized that users must move affected funds themselves, as developers are unable to access air-gapped devices or modify existing wallet seeds. The incident underscores a broader challenge in hardware wallet security: while devices like Coldcard are engineered to keep private keys offline, vulnerabilities introduced during wallet seed generation can persist undetected until exploited, leaving users reliant on prompt disclosure and migration to unaffected setups.