NewsCryptoColdcard Bitcoin Thefts Slow as Confirmed Losses Top $112 Million—and Could Exceed $150 Million: Galaxy Research

Coldcard Bitcoin Thefts Slow as Confirmed Losses Top $112 Million—and Could Exceed $150 Million: Galaxy Research

Author: Decrypt·

Key Takeaways

  • Galaxy Research said it has confirmed thefts of more than 1,778 BTC from the Coldcard exploit, worth about $112 million.
  • The firm said no confirmed attack waves or footprints have appeared after Aug. 6.
  • About 1,531 BTC remains unmoved in attacker-controlled addresses, while roughly 246 BTC has been moved after the theft.
  • Galaxy traced the exploit to a 2021 Coldcard firmware change that weakened seed generation security from 128 bits to as low as 40 bits.
  • Galaxy advised users still holding funds in single-signature Coldcard wallets to transfer them to new addresses.
Coldcard Bitcoin Thefts Slow as Confirmed Losses Top $112 Million—and Could Exceed $150 Million: Galaxy Research

Stolen Bitcoin losses from the massive Coldcard wallet exploit have begun to slow, but the total amount of BTC swiped continues to climb—and the worst may not be over just yet.

That's the latest from Galaxy Research, the crypto research firm that has been tracking the exploit from the start. The company said Thursday that the Coldcard seed-recreation exploit has now drained more than 1,778 BTC—roughly $112 million—and that the final figure will likely be higher.

Galaxy said it has "very high confidence" in the tally, which counts confirmed, owner-attributed thefts since the attack opened on July 30, per its running thread on X.

"Attackers have been executing this attack since at least early morning July 30, 2026, systematically recreating Coldcard-generated seeds and sweeping the funds onchain," Galaxy Research wrote.

Among Galaxy's confirmed waves and footprints, none shows activity after August 6. That doesn't mean the method stopped working—it means the easy targets are gone.

The bulk of funds have remained largely unmoved since stolen from victims. Of the at least 1,778 BTC that has been stolen, 1,531 BTC remains in attacker-controlled addresses unmoved. ~246 BTC has been moved by attackers after the theft, with 65% flowing into Coinjoin transactions… pic.twitter.com/OHjJkr1x6D

— Galaxy Research (@glxyresearch) August 14, 2026

What the chains show

Coldcard, made by Toronto-based Coinkite, is a Bitcoin-only hardware wallet long popular with self-custody users—a device marketed on the premise that private keys are generated and stored safely offline. A 2021 firmware update quietly rerouted Coldcard's seed generation off its hardware random-number chip and onto a software stand-in, collapsing key strength from 128 bits to as low as 40. That matters because the seed is a wallet's master secret—the recovery phrase from which every private key and address is derived—and 128 bits of entropy is the baseline security engineers consider infeasible to brute-force; 40 bits is not. Attackers could rebuild seeds from a device's serial number and clock state, then sweep the coins without resorting to phishing or malware techniques—and even without physical access to the actual devices.

Galaxy's breakdown puts the largest proven wave—Wave 1—at 1,082.65 BTC pulled from 1,195 addresses in the opening minutes. That was roughly $70.5 million worth of Bitcoin stolen at the time.

Footprint E, the biggest single owner-confirmed cluster, took 209.94 BTC (roughly $13.3 million) across 2,148 addresses, while Wave 3 took 208.24 BTC (near $13 million) from 1,912 addresses.

Across three proven waves and 41 smaller footprints, the firm charts more than 5,200 drained addresses. As of block 962,304 (data from August 13), 1,499.27 BTC—nearly $93.9 million—sat unspent in attackers' hands.

Among the confirmed, high-confidence waves and footprints of attacker activity, none occurred after August 6. Additional victims continue to report to Galaxy Research (we've spoken to 190+ directly), helping us directly attribute losses and confirm additional footprints, but none… pic.twitter.com/8jEdFdJEog

— Galaxy Research (@glxyresearch) August 14, 2026

Of the thin slice Galaxy can trace to a final endpoint—174.97 BTC—most went into coinjoin privacy rounds, transactions that pool coins from many participants to obscure which funds belong to whom, with small amounts reaching KuCoin and Jump Crypto. Galaxy has spoken with more than 190 victims directly to attribute losses.

"The abatement in attack waves is likely because vulnerable users have migrated or most funds have already been drained," the firm wrote.

Galaxy repeated its advice to holders: "If you still hold funds on a single-signature Coldcard wallet, you are advised to move your funds to new addresses." The warning singles out single-signature setups because multisignature wallets require several independent keys to authorize a spend, so one compromised seed doesn't by itself expose the funds.

The episode has already pushed roughly $15 billion in Bitcoin to safer custody and drawn a warning from rival hardware-wallet maker Ledger that wallet security has to adapt to AI-assisted discovery. Hardware-firm peers have also flagged a phishing surge riding the panic.

Galaxy still carries a candidate fourth wave—638.5 BTC it hasn't confirmed—that would lift the toll to 2,417 BTC, above $151.3 million at current prices. Whether that wave joins the confirmed tally, and whether the 1,531 BTC sitting in attacker-controlled addresses stays put, are the open threads to watch—and because Bitcoin's ledger is public, even unmoved stolen funds remain visible to anyone tracking the addresses.