Coldcard Bitcoin Thefts Slow, But Losses Could Top $150 Million: Galaxy
Galaxy Research reports Coldcard exploit thefts surpassed 1,778 BTC ($112M) and may exceed $150M. A 2021 firmware flaw enabled seed reconstruction. Victim reports continue, but no confirmed thefts after August 6; funds largely unmoved, with users urged to move to fresh addresses.
Quick Take
Galaxy confirms over 1,778 BTC stolen via Coldcard seed-recreation exploit.
2021 firmware update weakened seed entropy, enabling attackers to sweep funds.
No confirmed thefts after August 6, but losses may top $150M.
Single-signature users advised to move funds to fresh addresses.
Market Impact Analysis
BearishSecurity exploit undermines trust in hardware wallets, potentially triggering short-term bearish sentiment for Bitcoin, though contained to Coldcard users.
Speculation Analysis
Key Takeaways
- Galaxy Research confirms over 1,778 BTC ($112 million) stolen via Coldcard seed-recreation exploit, with 1,531 BTC still unmoved.
- The flaw stems from a 2021 firmware update that reduced seed entropy from 128 bits to as low as 40, enabling seed recreation.
- No confirmed thefts after August 6, but additional victim reports could push total losses beyond $150 million.
- Single-signature Coldcard holders should move funds to fresh addresses immediately; multi-signature setups appear unaffected.
What Happened
Galaxy Research's latest report shows the Coldcard wallet exploit has drained over 1,778 BTC, worth approximately $112 million. The attack began July 30, 2026, and no confirmed thefts occurred after August 6. Galaxy has spoken to more than 190 victims directly and identified three major waves plus 41 smaller footprints. The bulk of stolen funds remains in attacker-controlled addresses. Single-signature Coldcard holders are advised to move funds to fresh addresses, while multi-signature users appear unaffected.
The Numbers
Confirmed losses exceed 1,778 BTC, with 1,531 BTC still sitting in attacker addresses. About 246 BTC has been moved post-theft, with 65% flowing into CoinJoin transactions. The largest wave, Wave 1, drained 1,082.65 BTC from 1,195 addresses in the opening minutes. Footprint E, the biggest owner-confirmed cluster, took 209.94 BTC across 2,148 addresses, while Wave 3 took 208.24 BTC from 1,912 addresses. Across all waves, more than 5,200 addresses were drained. A potential fourth wave could push total theft to 2,417 BTC, over $150 million. The firmware flaw weakened seed strength from 128 bits to as low as 40 bits.
Why It Happened
The root cause traces to a 2021 Coldcard firmware update that silently moved seed generation from the hardware random-number chip to a software function. This change collapsed key strength from 128 bits to as low as 40 bits. Attackers could rebuild seeds using a device's serial number and clock state, without needing phishing, malware, or physical access. The systematic nature of the flaw allowed attackers to execute multiple waves, recreating seeds and sweeping funds on-chain.
Broader Impact
The exploit highlights a critical risk in hardware wallet firmware updates. While the damage appears contained to Coldcard single-signature users, the incident may erode trust in hardware wallets broadly and trigger short-term bearish sentiment for Bitcoin. It also underscores the need for rigorous entropy auditing in wallet software and could accelerate adoption of multi-signature setups.
What to Watch Next
- Additional victim reports could push total losses beyond $150 million, possibly to 2,417 BTC.
- Monitor attacker movements of the remaining 1,531 BTC; CoinJoin usage suggests ongoing laundering efforts.
- Watch for Coldcard's firmware fixes and user guidance; verify seed generation changes before using wallets.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.