Coldcard Theft Expands to $88M Across Three Waves as Exchange Inflows Surge and Dormant Bitcoin Stirs
Key Takeaways
- •A coordinated three-wave attack stole roughly 1,158.848 BTC, valued at about $88.6 million, from 4,585 addresses linked to vulnerable Coinkite Coldcard hardware wallets.
- •The exploited vulnerability originated from a specific Coldcard firmware update distributed on March 17, 2021, which primarily affected long-term cold storage holders.
- •The attacker altered their strategy during the third wave by dispersing the stolen funds across 293 concealed P2WSH vaults, significantly complicating blockchain tracing efforts.
- •Centralized cryptocurrency exchanges experienced a notable spike of 11,163 BTC in net inflows on July 31, though this activity has not been definitively linked to the incident.
- •Galaxy Research is actively monitoring the identified holding addresses and vaults, anticipating that future transactions may reveal the perpetrator's identity through exposed spending conditions.

Coldcard Theft Expands to $88M Across Three Waves as Exchange Inflows Surge and Dormant Bitcoin Stirs
Three Suspicious Sweeps Drain 4,585 Addresses
Galaxy Research disclosed on X that three suspected waves of theft drained approximately 4,585 addresses and seized bitcoin valued at roughly $88.6 million at the time of analysis. The firm emphasized that its findings remain preliminary, drawn solely from publicly available Bitcoin blockchain data. A separate tracking dashboard, Coldcard Sweep Watch, recorded the total at 1,158.8480 BTC as of 5 p.m. EDT on Saturday.
The largest of the three waves came first. On July 30, an attacker swept 1,082.65 BTC from 1,195 addresses in just 41 minutes, according to Galaxy's researchers. A second operation the following day collected 76.16 BTC from 1,478 addresses. The third wave, spanning July 31 into August 1, drained approximately 208 BTC from 1,912 addresses.
Wave Three Breaks Pattern, Raising Questions About the Attacker's Identity
The third operation diverged methodologically from the first two. Waves 1 and 2 funneled stolen funds through a small set of collector and holding addresses. Wave 3, by contrast, distributed victims' bitcoin across 293 separate P2WSH vaults—a type of native SegWit address that conceals its spending conditions until coins are moved.
Galaxy noted that the fragmented vault structure makes it significantly harder for outside observers to cluster and trace the funds. The shift could indicate that the original attacker restructured the operation after the initial sweeps became public knowledge. Alternatively, a separate party may have independently identified and exploited the same pool of vulnerable addresses. Blockchain records alone cannot resolve which scenario is accurate.
Vulnerability Traced to 2021 Coldcard Firmware Release
Galaxy linked the exploited addresses to a vulnerable Coinkite Coldcard firmware version distributed on March 17, 2021. Significantly, none of the affected coins predate that firmware release. The median victim address had been dormant for approximately 3.5 years, consistent with the usage patterns of long-term cold storage holders.
Coldcard is a Bitcoin-only hardware wallet manufactured by Coinkite and marketed for its air-gapped security model, in which private keys are intended never to touch an internet-connected device. The incident underscores that even wallets designed for offline key storage can carry exploitable weaknesses introduced through firmware—a concern that extends across the hardware wallet sector, where device security depends heavily on the integrity of the software running on the device itself.
Exchange Inflows Spike on July 31
While researchers mapped the theft, centralized cryptocurrency exchanges logged a dramatic surge in bitcoin deposits on July 31. Data shared by Sani of Timechainindex.com showed net exchange inflows of 11,163 BTC for the day.
River received an estimated 3,679 BTC, followed by Binance with 3,224 BTC, Kraken with 2,848 BTC, and OKX with 1,291 BTC. Collectively, centralized entities received 15,205 BTC from unidentified addresses in a single day, substantially boosting their reported holdings.
Large exchange inflows typically draw scrutiny because coins moved to trading platforms may be destined for sale, posted as collateral, or shifted for internal custody reasons. The data does not confirm that any of the July 31 deposits originated from Coldcard users, the attacker, or parties reacting to the incident. Still, the timing is notable—a security event of this nature can prompt holders to restructure their storage, relocate coins to exchanges, or abandon wallet configurations they no longer trust. The inflow spike could equally reflect unrelated institutional transfers, routine customer deposits, or exchange bookkeeping activity, making it significant but ultimately inconclusive.
Long-Dormant Bitcoin Wallets Show Renewed Activity
A separate development surfaced as numerous addresses created between 2010 and 2017 began moving coins after nine to sixteen years of dormancy. Statistics compiled by Bitcoin.com News from btcparser.com showed that visible transactions from July 30 through August 1 totaled approximately 306 BTC, including repeated transfers of 10 BTC and 30 BTC.
One address created on July 2, 2010, transferred an old coinbase transaction exceeding 50 BTC. Additional transactions included 37.8 BTC from a 2014-origin address and a coordinated set of transfers from three wallets created on July 29, 2017. Those three wallets moved 37.5 BTC alongside two separate 30 BTC transfers, all confirmed in the same block.
The dormant activity cannot be definitively linked to the Coldcard sweeps. Galaxy Research noted that all suspected victim coins were created after the vulnerable firmware shipped in 2021, while many of the newly active dormant wallets held bitcoin years before Coldcard existed. Nevertheless, as with the exchange inflows, long-inactive BTC holders may be reassessing their security arrangements and relocating assets to alternative storage, including custodial services.
Researchers Continue Monitoring Holding Addresses and Vaults
Galaxy Research stated that it is actively monitoring seven holding addresses associated with the first two waves and 293 vaults from the third. The first spend from any of those vaults could expose the underlying scripts, potentially revealing whether identical signing keys or spending structures appear across multiple addresses. Such a revelation would allow the broader blockchain analysis community to apply clustering techniques and potentially link the third wave to the earlier operations—or to an entirely different actor.
At press time, BTC was trading at $62,326.