Coldcard hackers leave 87% of stolen Bitcoin unmoved after $114M theft
More than 87% of the Bitcoin attributed to the Coldcard hack has remained unmoved, leaving 1,561 BTC under attacker control after researchers linked the exploit to $114.7 million in losses.
Summary
- Galaxy Research traced 1,789 BTC stolen from 8,865 addresses to the Coldcard hack.
- About 1,561 BTC, or 87.3% of the attributed losses, remains unmoved.
- Some Bitcoin from later attacks has moved through CoinJoin transactions and peel chains.
- Galaxy has shared identified attacker addresses with exchanges, compliance firms and law enforcement.
Galaxy Research has traced 1,789.28 BTC stolen from 8,865 addresses to the Coldcard exploit, according to a Monday X post from Alex Thorn, the firm's head of research. The Bitcoin was worth $114.7 million when it was taken, while Thorn put its current value at about $138.8 million.
📊 updated numbers on coldcard exploit
8865 addresses lost 1789.28 BTC worth $114.7m at the time of theft ($138.8m today)
-- loss by address
median 0.00152
mean 0.20184
dormancy median 3.2yr
dormancy mean 3.6yr
-- loss by victim reports (221)
median 1.04272
mean 3.57792
dormancy... pic.twitter.com/d2R29dYyco --- Alex Thorn (@intangiblecoins) August 24, 2026
Of the total, 1,561 BTC, or 87.3%, has not been spent and remains in collection or holding addresses controlled by the attackers. All Bitcoin tied to the first three identified attack waves has also remained unmoved, giving researchers an onchain record of where a large portion of the stolen funds is being held.
Some funds from later attacks have started moving. Thorn said attackers have used CoinJoin transactions, peel chains and other methods designed to make the movement of Bitcoin harder to follow across addresses.
Most Bitcoin from the Coldcard hack remains traceable
Galaxy's latest figures include both address-level analysis and information submitted directly by victims as researchers continue mapping wallets connected to the exploit.
Across the 8,865 addresses identified by the firm, the median loss was 0.00152 BTC and the average stood at 0.20184 BTC, according to figures shared by Thorn. The affected Bitcoin had also remained dormant for long periods before being stolen, with median address dormancy of 3.2 years and an average of 3.6 years.
Victim reports show heavier losses on an individual basis. Galaxy has received 221 reports covering 790.72 BTC, equivalent to 44.2% of the total Bitcoin attributed to the exploit. The median reported loss was 1.04272 BTC and the average was 3.57792 BTC.
Thorn clarified separately that the median means at least half of the 221 reporting victims lost 1 BTC or more. Bitcoin covered by those reports had remained dormant for a median of 3.25 years before the theft, while the average dormancy period was 2.99 years.
You might also like: Coldcard theft: FBI may know 1,082 BTC attacker
The confirmed tally may not account for every loss linked to the incident. Thorn said that including medium-confidence addresses not yet confirmed would increase the estimate to about 1,824 BTC, worth roughly $140 million at the time of the respective thefts.
Earlier estimates changed as researchers identified additional victim addresses and attack patterns. TRM Labs said on Aug. 5 that the incident had involved several waves beginning July 30 and traced the thefts to a firmware problem that weakened the randomness used when generating some Coldcard wallet seeds.
According to TRM Labs, a build configuration error introduced through firmware in March 2021 caused affected devices to fall back on a weaker software random number generator instead of relying fully on hardware-generated entropy. The security firm said the resulting key strength could fall low enough for private keys to be recovered through brute-force computing without physical access to the wallet.
Attackers have started obscuring some later thefts
While the largest holdings remain parked, Galaxy has found different transaction behavior among funds taken during later attacks.
CoinJoin can combine transactions from multiple participants to make it more difficult to connect individual inputs with their eventual outputs. Peel chains involve repeatedly moving smaller amounts from a larger balance into new addresses, creating longer transaction trails for investigators to follow.
Galaxy has continued tracking those movements while sharing identified attacker addresses with cryptocurrency exchanges, compliance companies and law enforcement. Thorn said the effort could allow centralized platforms to identify and potentially freeze stolen Bitcoin if attackers eventually send funds into services where accounts or transactions can be intercepted.
The lack of movement across the first three waves is particularly important to the tracing effort because the corresponding Bitcoin has not yet passed through the obfuscation techniques observed in later activity. Researchers can therefore continue monitoring known addresses for outgoing transactions.
Earlier in August, TRM Labs also reported that most stolen funds were pooling in a limited number of attacker-controlled addresses with little onward movement at the time. Differences between transaction structures across the attack waves led the company to say multiple attackers could have been involved, although it did not attribute the exploit to any specific actor.
Coldcard security had focused on offline key storage
The incident has put attention on a hardware wallet brand built specifically around Bitcoin self-custody.
In May, crypto.news previously reported that Coinkite had released the Coldcard MK5, its first hardware revision to the flagship MK line since the MK4 arrived in 2022. The device retained a dual secure-element design using components from two chip manufacturers and continued supporting air-gapped transaction workflows.
The MK5 also introduced a larger Gorilla Glass display, redesigned physical buttons and improved NFC functionality. Coinkite said at the time that the device continued using open-source firmware while keeping its Bitcoin-only design.
Wallet security had already faced increased attention before the Coldcard losses surfaced. In July, Coinspect disclosed a weakness it called "Ill Bloom," which involved poor randomness during recovery-phrase generation across several software wallets. The security company said about $5 million had moved from exposed wallets by early July, although hardware wallets appeared unaffected by that particular issue.
Weak randomness can become especially dangerous in cryptocurrency wallets because seed phrases ultimately determine the private keys controlling the assets. If the random input used to create a seed contains too little entropy, an attacker with enough computing resources may be able to search the reduced range of possible combinations.
-- Price
Hardware wallet risks have drawn fresh scrutiny
Other wallet security incidents this summer have involved different attack methods.
Ledger's Donjon researchers in July demonstrated a laser attack against a Tangem wallet card that could reset its password and potentially allow transactions to be signed. Tangem said the method required physical possession of the card, specialist knowledge and laboratory equipment costing around $250,000, making the attack different from a remotely exploitable wallet weakness.
Onchain investigator ZachXBT had also criticized hardware wallets in July, saying he did not consider existing devices suitable for signing critical transactions or holding large amounts of cryptocurrency. His comments represented a personal assessment and were not tied to evidence of a new hardware compromise at the time.
The Coldcard incident involves a different failure point because researchers linked the thefts to seed generation on affected devices. TRM Labs said installing updated firmware does not repair a seed that was originally created with weak randomness, meaning users with affected wallets would need to generate a new seed on secure hardware and transfer their Bitcoin to addresses derived from it.
For investigators, the stolen Bitcoin itself remains the main source of evidence. Galaxy has continued distributing confirmed attacker addresses to exchanges, compliance firms and law enforcement while monitoring the 1,561 BTC that has yet to leave attacker-controlled collection and holding wallets.
Read more: Monad proposes wallet upgrade for passkeys, recovery and quantum security
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Samsung Wallet Adds USDC on Solana for 82 Million US Galaxy Devices: What Launches in October and What Remains Unconfirmed

Citrini Research Points Out That the 'Wall' Between Traditional Finance and Cryptocurrency Is Beginning to Crumble

What is being said at the tables: Flávio Bolsonaro and Scott Bessent give air to Luis Caputo, but the market charges for the activity

Citrini Highlights AI Financial Stocks and Coins: 8 Listed Companies, 1 ETF, 15 Coins

Economist Who Called Bitcoin 'Revolutionary' Among Favorites for 2026 Nobel Prize in Economics

US Government Transfers 12267 BTC Worth 1010000000 USD from Bitfinex Hacker Seizure

From Web3 to the Real Economy: Erable° Becomes an Essential Player in Impact Financing

XDP Coin Price Drops Below $0.02 After Its September Listing: What Is Behind Doppler Finance's Post-Launch Slide?

Ledger Wallet – October 2026: Circulating Your Cryptos Without Losing Control

Money20/20 USA 2026: How Bitcoin, Stablecoins And AI Are Reshaping The Future Of Finance

SoFi Tech Solutions, Orbi, and Mastercard Partner to Launch Cryptocurrency-Linked Card in Mexico

Cedears: Record Rates, Euphoria for AI, and Brazil Reshaping the Stock Map—What Could Happen Next?

US Moves $470 Million in Crypto: What Does This Signal?

What Is Your Crypto Trading MBTI? Take the WEEX Personality Test
Discover what the WEEX Trading MBTI test at TOKEN2049 Singapore explores, how trading habits shape decision-making, and how to use your result constructively.

Standard Chartered plans institutional crypto custody service in Singapore

2.6 Trillion KOK Coin Fraud Case, Calls for Strengthening FIU Role in National Assembly

How Cryptocurrency is Fundamentally Reshaping the Financial System: A Conversation with a16z Partner
![[Exclusive] MemeCore "Has Never Sold Foundation's Holdings... September Transfers Were for Liquidity Supply"](/public-static/9_8dc682caea.png?format=avif)
[Exclusive] MemeCore "Has Never Sold Foundation's Holdings... September Transfers Were for Liquidity Supply"

U.S. Consumer Credit Cools Due to Sharp Drop in Credit Cards

September FOMC Meeting Minutes Released; Possibility of Further Rate Hike Exists

Capital Markets Increase Governance Requirements: Analysis by ID CTVM

Why Is VIX Rising Today? What VIX Means for Stocks and Bitcoin

Why did the US government send $71M in Bitcoin to Coinbase Prime?

Solana Launches Digital Payment Platform for Institutional Investors in Collaboration with JP Morgan

Wintermute Declares Early Stage of Crypto Bull Cycle

Solana launches tool to settle bank trades in seconds

How Are RWA Assets Tokenized in Hong Kong?

BitGo shifts focus from crypto custody to trading, lending

Bitcoin Fear and Greed Index: How It Works










