📈 Get daily crypto insights that make you smarter about your money

The Coldcard Wallet Hack Is Slowing Down — but 112 Million in Bitcoin Is Already Gone and a Fourth Wave Could Push Losses Past 150 Million

One of the biggest wallet hacks in Bitcoin history is finally slowing down — but the bill keeps growing. On Thursday, Galaxy Research said the Coldcard wallet exploit has now drained more than 1,778 Bitcoin, worth roughly 112 million dollars at current prices, and warned that a suspected fourth wave of thefts could push total losses past 150 million.

By Sarah Park | August 15, 2026

The Hack That Turned a Security Device Into an Open Vault

The Coldcard wallet hack is one of the largest self-custody disasters Bitcoin has ever seen — and it did not involve phishing emails, fake apps, or stolen passwords. According to Galaxy Research, the crypto research firm that has tracked the attack from day one, the root cause was a 2021 firmware update that quietly changed how Coldcard devices generated the secret recovery phrases protecting users’ coins.

Instead of using the device’s dedicated hardware random-number chip — think of it as a casino-grade dice roller — the update switched to a weaker software stand-in. Galaxy says this collapsed the strength of generated seeds from 128 bits down to as low as 40 bits. In plain English: your 12 or 24 backup words were supposed to be picked from an ocean of possibilities, but they were actually picked from a puddle. Attackers could rebuild a wallet’s secret phrase using nothing more than a device’s serial number and clock state, then sweep the coins without ever touching the physical device.

The attacks have been running since at least July 30, 2026, Galaxy says, with thieves “systematically recreating Coldcard-generated seeds and sweeping the funds onchain.”

What the Blockchain Shows

Because every Bitcoin transaction is public, researchers can watch the crime scene in real time. Galaxy’s breakdown of the confirmed theft waves reads like a bank heist audit:

  • Wave 1 — 1,082.65 Bitcoin pulled from 1,195 addresses in the opening minutes, worth about 70.5 million dollars at the time
  • Wave 3 — 208.24 Bitcoin taken from 1,912 addresses, near 13 million dollars
  • Largest single victim cluster — 209.94 Bitcoin across 2,148 addresses, roughly 13.3 million dollars
  • Total footprint — more than 5,200 drained addresses across three proven waves and 41 smaller footprints
  • Still sitting in thief wallets — about 1,531 Bitcoin of the stolen haul remains unmoved in attacker-controlled addresses

Of the roughly 246 Bitcoin the attackers have shuffled around since the thefts, about 65 percent flowed into “coinjoin” transactions — a privacy technique that mixes coins together like shuffling a deck of cards to hide their origin. Small amounts have reached the exchange KuCoin and crypto firm Jump Crypto, according to Galaxy’s tracing. The firm has now spoken with more than 190 victims directly to confirm losses.

Why the Attacks Are Fading — and Why That Is Not All Good News

Here is the strange part: across all confirmed waves and footprints, not one shows attacker activity after August 6. Galaxy is careful about what that means. “The abatement in attack waves is likely because vulnerable users have migrated or most funds have already been drained,” the firm wrote. In other words, the thieves may not have stopped because they were blocked — they may have stopped because there is little left that is easy to steal.

The panic has had one silver lining: roughly 15 billion dollars in Bitcoin has reportedly moved to safer custody arrangements since the exploit became public. But Galaxy still carries a candidate fourth wave — 638.5 Bitcoin it has not yet confirmed — which would lift the total to 2,417 Bitcoin, worth more than 150 million dollars at today’s prices. And hardware wallet firms have warned of a phishing surge riding on the fear, with scammers impersonating recovery services. Ledger has also warned that wallet security must now adapt to AI-assisted discovery of flaws.

What This Means for Your Bitcoin

If you own a Coldcard and still hold funds on a single-signature wallet — one key, no extra approvals — Galaxy’s advice is blunt: move your funds to brand-new addresses generated by different software. Multisig setups, which require several keys to move coins, have proven far less exposed to this style of attack.

For everyone else, the lesson is simpler. “Not your keys, not your coins” only protects you if the keys themselves were generated properly. Buy hardware wallets direct from the manufacturer, never from resellers, and treat any wallet bought before a major firmware change with fresh eyes.

The Verdict

Bitcoin itself is trading around 62,900 dollars, barely moving on the news — because this was never a Bitcoin protocol failure. It was a device failure, the equivalent of a lock factory shipping thousands of locks that all opened with the same key. The network worked exactly as designed; the wallet did not. For a market that has spent 2026 arguing that self-custody is the future, the Coldcard hack is the most expensive reminder yet that with great control comes great responsibility — and that “hardware wallet” on the box is not a guarantee, it is a claim you should verify.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

Disclaimer: This article is for informational purposes only and does not constitute financial advice.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

25 thoughts on “The Coldcard Wallet Hack Is Slowing Down — but 112 Million in Bitcoin Is Already Gone and a Fourth Wave Could Push Losses Past 150 Million”

  1. coldcard_mourner

    a firmware change from 2021 broke seed generation and it sat there for five years. five years! and we wonder why normies don’t self custody

    1. hw_audit_or_bust

      coldcard_mourner five years of a broken seed generation function and no external audit caught it. self custody means self auditing apparently

  2. Genuinely asking, why would the attacker just stop on August 6? Either they got what they came for or they’re waiting for the heat to die down. Neither option is comforting.

    1. or they’re laundering through mixers and don’t want new thefts linking wallets back to the same cluster. galaxy mapped the waves for a reason

    2. 40 bit keyspace means the weak seed list is finite and crackable in seconds. pausing august 6 reads like opsec once galaxy started mapping the cluster publicly

    3. Biniam T. exactly, the whole pitch was trusting the chip and the chip was the thing that lied. dice entropy looks paranoid until this happens

  3. five years of ‘not your keys not your coins’ lectures and the keys themselves were the broken part. brutal. galaxy earning their keep tracing this

  4. 1778 btc gone because of a firmware update from 2021. five years of silently bad entropy and nobody noticed. unreal

    1. the worst part is the bug sat there since 2021. every security audit and every verifiable build claim missed it

  5. I stopped trusting single-vendor hardware wallets after this one. 112 million dollars is expensive tuition for that lesson.

    1. ok but what does multi vendor even look like in practice. three devices, three seeds, dice on each? most people quit by week two and consolidate back to one anyway

    2. Moved to a 2-of-3 multisig across three vendors after this one. That 112 million number convinced me convenience was the real attack surface.

      1. 2-of-3 across vendors is the move but most people learned it only after 112M walked out. convenience wins until it catastrophically doesnt

        1. seed_split_check

          rusted_keyring the 2-of-3 across vendors advice is solid but the attack surface is the seed generation itself. if coldcard generated a weak seed in 2021 no multisig scheme downstream fixes that

          1. seed_split_check this is the detail nobody wants to hear. my coldcard seed is from 2022, now I get to redeploy an entire vault because downstream hygiene cannot save an upstream failure

          2. seed gen is the foundation. a 2-of-3 built on weak seeds is just three doors into the same empty room

  6. does the 150 million estimate assume btc holds here or is it a moving target? asking because that math changes fast

    1. entropy_witness

      galaxy said 1778 btc swept already and the fourth wave is still suspected. so yeah moving target, depends how many weak seeds are still sitting in old drawers

      1. moving target is right, every weak seed still out there is a lottery ticket for whoever holds the list. the 150M estimate assumes they get bored

  7. 128 bits down to 40 because a 2021 update swapped a hardware rng for a software call. four years of audits and verifiable builds staring right past it

  8. the galaxy cluster mapping is the only reason this slowed down. thieves dont pause out of mercy, they pause when tracing gets easy

    1. Galaxy mapping the cluster pattern was the inflection point. before that every coldcard user was a potential target. now at least the list of affected devices is shrinking

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,899.00+0.4%ETH$2,405.86-0.6%SOL$100.77+0.7%BNB$697.43+1.4%XRP$1.37+1.5%ADA$0.2060+4.5%DOGE$0.0831+1.8%DOT$0.8772+1.8%AVAX$7.29+0.9%LINK$11.24-0.1%UNI$5.70-9.2%ATOM$1.49+2.2%LTC$50.46+2.2%ARB$0.1339+17.0%NEAR$1.89+1.5%FIL$0.8004+0.9%SUI$0.7695+6.0%BTC$77,899.00+0.4%ETH$2,405.86-0.6%SOL$100.77+0.7%BNB$697.43+1.4%XRP$1.37+1.5%ADA$0.2060+4.5%DOGE$0.0831+1.8%DOT$0.8772+1.8%AVAX$7.29+0.9%LINK$11.24-0.1%UNI$5.70-9.2%ATOM$1.49+2.2%LTC$50.46+2.2%ARB$0.1339+17.0%NEAR$1.89+1.5%FIL$0.8004+0.9%SUI$0.7695+6.0%
Scroll to Top