Coldcard Exploit: 87% of $114.7M Stolen Bitcoin Remains Unmoved, Over Half of Victims Lost More Than 1 BTC

3 hour ago 3 sources negative

Key takeaways:

  • Stolen Bitcoin's dormancy suggests attackers may wait for lower scrutiny before laundering.
  • Hardware wallet flaws underscore that even air-gapped devices rely on secure randomness.
  • Watch for sudden BTC moves to exchanges; Galaxy's exchange alerts may trigger freezes.

Galaxy Research has linked the Coldcard hardware wallet exploit to 1,789.28 BTC stolen from 8,865 addresses, a haul worth roughly $114.7 million at the time of theft and about $138.8 million at current prices. In updated figures shared by Alex Thorn, the firm’s head of research, on Aug. 24, analysts said 1,561 BTC—or 87.3% of attributed losses—remains unmoved in attacker-controlled collection or holding addresses.

The immobility is especially notable for the first three identified attack waves: all Bitcoin tied to those waves has stayed in place, giving investigators a clear onchain record. Some funds from later attacks have begun moving through CoinJoin transactions, peel chains and other obfuscation techniques, but researchers say most of the stolen value remains traceable.

Galaxy’s address-level analysis shows a median loss of 0.00152 BTC and a mean of 0.20184 BTC. The affected addresses had been dormant for a median of 3.2 years and an average of 3.6 years before the theft. Victim-submitted reports reveal heavier individual losses: 221 reports covered 790.72 BTC, equivalent to 44.2% of the total attributed haul. The median reported loss was 1.04272 BTC and the average was 3.57792 BTC, meaning more than half of reporting victims lost over one full bitcoin. Thorn noted that including medium-confidence addresses could raise the estimate to about 1,824 BTC, worth roughly $140 million at the time of the respective thefts.

TRM Labs said on Aug. 5 that the incident began in several waves starting July 30 and traced the thefts to a firmware problem that weakened the randomness used when generating some Coldcard wallet seeds. A build configuration error introduced through firmware in March 2021 caused affected devices to fall back on a weaker software random number generator instead of relying fully on hardware-generated entropy. The resulting key strength could fall low enough for private keys to be recovered through brute-force computing without physical access to the wallet. TRM Labs also noted that installing updated firmware does not repair a seed that was originally created with weak randomness; affected users would need to generate a new seed on secure hardware and move their Bitcoin to addresses derived from it.

The exploit has put renewed attention on Coldcard, a Bitcoin-only hardware wallet built around self-custody. Coinkite released the Coldcard MK5 in May, retaining a dual secure-element design and air-gapped workflows. The incident follows other wallet security concerns, including Coinspect’s Ill Bloom weakness and Ledger’s Donjon laser attack research against a Tangem card.

Galaxy has shared identified attacker addresses with cryptocurrency exchanges, compliance firms and law enforcement. The hope is that centralized platforms can identify and possibly freeze stolen Bitcoin if attackers eventually send funds into services where accounts or transactions can be intercepted. For now, most of the haul remains parked and visible onchain, but visibility alone does not guarantee recovery while the assets stay under attacker control.

Previously on the topic:
Aug 19, 2026, 8:19 a.m.
FBI May Have Identified Coldcard Hacker Behind 1,082 BTC Theft
Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.