Coldcard drain tally climbs to ~$90M as attackers keep sweeping single-sig sats 🧊
Galaxy Research has identified a fourth wave of Bitcoin thefts tied to the Coldcard wallet exploit, with the latest batch moving roughly 388.9 BTC across 218 transactions impacting 462 potential victim addresses, according to an X post Monday by Galaxy head of research Alex Thorn. Thorn said the activity averaged 13.8 sweeps per block, about 45 times the rate seen in a pre-incident control window, with most transfers creating a fresh destination per victim rather than converging on a central collection wallet and some funds already swept into second-hop addresses.
The total observed losses now stand at roughly $90 million across more than 1,100 wallets, based on Galaxy's running tally. The research arm of Galaxy Digital first identified 1,196 addresses linked to the Coldcard incident that lost 1,082.65 BTC, worth about $70.2 million at the time of the transactions, in a Friday X post tracing Bitcoin movements between 1:10 AM and 1:51 AM UTC on July 30 across blocks 960,183 to 960,191. By Saturday, Galaxy had flagged a third wave draining 207.73 BTC, lifting the observed tally to about 1,367 BTC, around $88.6 million, across 4,585 addresses, with about 600 suspected attacker addresses shared with federal investigators, compliance firms and cross-industry cyber investigators.
The three documented waves share a pattern, including identical 30 satoshis per virtual byte fees and no change outputs, which Galaxy said makes the initial attack activity identifiable on-chain but warned that future attacks against Coldcard-generated addresses may not follow the same fingerprint. "I continue to investigate and add new Coldcard victim and attacker addresses to our investigation database tonight THE ATTACK IS ONGOING -- move your funds off Coldcard-generated addresses immediately if you have not done so. i will provide additional updates on estimated…" Thorn posted on X on August 2, 2026. Thorn wrote that the sweeps appear deliberate and programmatic, possibly orchestrated with a large language model, and cautioned that every single-sig Coldcard address created after a March 2021 firmware update will eventually be drained, noting an average dormancy of 3.18 years before the stolen coins were taken. The funds from the documented waves remain parked in attacker addresses and have not moved.
The flaw stems from a March 2021 firmware build error on Coinkite's devices that caused seed phrases to be generated with too little randomness, leaving private keys guessable. Coinkite co-founder Rodolfo Novak said in an X post on Friday that the company takes responsibility for the firmware bug and is working to determine the full scope, adding that a hotfix was released to remove the software fallback path but warning that the update does not protect seeds generated on vulnerable firmware and advising users who generated seeds on vulnerable firmware to move their funds to a new seed. An earlier preliminary analysis by AnchorWatch CEO and co-founder Rob Hamilton estimated that 594.48 BTC, worth around $38 million, moved across 500 transactions within a three-block window.
Affected users are moving Bitcoin off self-custody to centralized crypto exchanges including Coinbase and Binance or to freshly generated addresses, an inversion of the industry's usual "not your keys, not your coins" ethos. Canadian coach Jonathan Goodman said in an X post that 18.25 BTC, worth about $1.6 million Canadian, was swept from his Coldcard on July 29, with his keys kept on a Coldcard device in a safety deposit box that had never been connected to the internet.
Mentioned Coins
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.