NewsCryptoColdcard Bitcoin Exploit Climbs to $88.6 Million as Attackers Continue Draining Vulnerable Wallets

Coldcard Bitcoin Exploit Climbs to $88.6 Million as Attackers Continue Draining Vulnerable Wallets

Author: Decrypt·

Key Takeaways

  • Galaxy Research is tracking approximately $88.6 million in stolen Bitcoin across 4,585 addresses following a third wave of thefts from compromised Coldcard hardware wallets.
  • The vulnerability originates from a March 2021 Coinkite firmware build error that produced seed phrases with insufficient randomness, making private keys guessable.
  • Galaxy has flagged roughly 600 suspected attacker addresses to federal investigators, compliance firms, and cross-industry cyber investigators.
  • The stolen coins had remained untouched for an average of 3.18 years before being systematically swept, indicating that victims were primarily long-term holders.
  • Canadian coach Jonathan Goodman reported losing 18.25 BTC valued at approximately $1.6 million Canadian despite storing his device in a safety deposit box that was never connected to the internet.
Coldcard Bitcoin Exploit Climbs to $88.6 Million as Attackers Continue Draining Vulnerable Wallets

The theft of Bitcoin from compromised Coldcard hardware wallets remains an active and escalating threat, with Galaxy Research now tracking approximately $88.6 million in stolen funds across 4,585 addresses in three separate waves.

On Saturday, Galaxy Research announced it had identified a third wave of thefts in which 207.73 BTC was drained, bringing its observed total to roughly 1,367 BTC—about $88.6 million—spread across 4,585 addresses. The firm characterized the exploit as ongoing and urged anyone holding single-signature funds on a Coldcard device to relocate them immediately.

Galaxy stated that it has flagged approximately 600 suspected attacker addresses to federal investigators, compliance firms, and cross-industry cyber investigators. The firm credited victims who shared their transaction details for helping map the on-chain patterns used to trace the stolen funds.

"I continue to investigate and add new Coldcard victim and attacker addresses to our investigation database," said Alex Thorn, Galaxy's head of research, in a post on X. "The attack is ongoing—move your funds off Coldcard-generated addresses immediately if you have not done so."

i continue to investigate and add new Coldcard victim and attacker addresses to our investigation database tonight

THE ATTACK IS ONGOING -- move your funds off Coldcard-generated addresses immediately if you have not done so. i will provide additional updates on estimated…

— Alex Thorn (@intangiblecoins) August 2, 2026

The vulnerability, as Decrypt previously reported, originates from a March 2021 firmware build error on devices manufactured by Coinkite. The flaw caused seed phrases to be generated with far too little randomness, rendering private keys guessable. Because proper entropy in seed generation is foundational to all cryptocurrency security, the compromised randomness undermined the core cryptographic guarantee that hardware wallets are designed to provide—even for devices that were air-gapped and never connected to the internet.

Thorn wrote that the wallet sweeps appear deliberate and programmatic, most likely orchestrated with the assistance of a large language model. He cautioned that every single-signature Coldcard address created after the 2021 firmware update will eventually be drained, describing it as only a matter of time.

Thorn also noted that the stolen coins had sat untouched for an average of 3.18 years before being taken, highlighting that the victims were predominantly long-term holders. The multi-year gap between the firmware's introduction and the current exploitation helps explain why addresses accumulated across such a large window before being systematically targeted. The funds from the three documented waves remain parked in attacker addresses and have not yet moved.

The fallout has triggered a broad and alarmed response from affected users, with security experts urging caution when relocating funds to new addresses. Many users are racing to move Bitcoin off self-custody and back onto centralized crypto exchanges such as Coinbase or Binance, or to freshly generated addresses—an inversion of the industry's familiar "not your keys, not your coins" ethos.

For some users, the warnings arrived too late. Canadian coach Jonathan Goodman said in a post on X that 18.25 BTC—worth approximately $1.6 million Canadian—was swept from his wallets in a seven-minute span on July 29, despite his keys being stored in a safety deposit box that had never been connected to the internet.

$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack.

My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.

This part's nerdy, but here's…

— Jonathan Goodman 🇨🇦 (@itscoachgoodman) August 1, 2026

"Perhaps the hardest part about this is that I did everything right," Goodman wrote. He added that he is filing reports with police and the Ontario Securities Commission.