Summary
- The ongoing Coldcard exploit has resulted in approximately $88.6 million being stolen across 4,585 addresses in three separate incidents, according to Galaxy Research.
- Galaxy's Alex Thorn indicated that the thefts appear to be systematic and potentially driven by large language models, cautioning that all single-signature Coldcard addresses created following a March 2021 firmware vulnerability will eventually be compromised.
- This incident has prompted a notable shift away from the "not your keys, not your coins" philosophy, as many users are transferring Bitcoin back to exchanges.
The theft of Bitcoin from compromised Coldcard hardware wallets is still ongoing, with researchers estimating losses to be around $88 million and warning that every vulnerable device may soon be emptied.
Galaxy Research reported on Saturday that it had detected a third wave of thefts, where 207.73 BTC was stolen, bringing the total to approximately 1,367 BTC, valued at around $88.6 million, across 4,585 addresses. The firm described the exploit as ongoing and advised anyone with single-signature funds on a Coldcard to transfer them immediately. They have identified around 600 suspected attacker addresses and have reported these to federal authorities, compliance firms, and cybersecurity investigators, attributing some of their findings to victims who shared transaction information.
“I continue to investigate and add new Coldcard victim and attacker addresses to our investigation database,” stated Alex Thorn, head of research at Galaxy, in a post on X. “The attack is ongoing—move your funds off Coldcard-generated addresses immediately if you have not done so.”
i continue to investigate and add new Coldcard victim and attacker addresses to our investigation database tonight
THE ATTACK IS ONGOING -- move your funds off Coldcard-generated addresses immediately if you have not done so. i will provide additional updates on estimated…
— Alex Thorn (@intangiblecoins) August 2, 2026
The vulnerability stems from a firmware error in March 2021 on Coinkite's devices, which caused seed phrases to be generated with insufficient randomness, making private keys susceptible to guessing. Thorn noted that the thefts appear methodical and likely executed using a large language model, warning that every single-signature Coldcard address created post-2021 update is at risk of being drained over time.
Thorn observed that the stolen coins had remained untouched for an average of 3.18 years, indicating that the victims were long-term holders. The funds from the three identified waves of theft have not moved from the attackers' addresses.
This situation has elicited a frantic response from those affected, with security experts advising caution when transferring funds to new addresses. Many users are hurriedly moving their Bitcoin away from self-custodial wallets back to centralized exchanges like Coinbase or Binance, which contradicts the typical "not your keys, not your coins" philosophy prevalent in the industry.
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack.
My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.
This part's nerdy, but here's… pic.twitter.com/Lf9kJv9Jo4
— Jonathan Goodman 🇨🇦 (@itscoachgoodman) August 1, 2026
For some individuals, the alerts came too late. Canadian coach Jonathan Goodman reported on X that 18.25 BTC, equivalent to about $1.6 million Canadian, was stolen from his wallets in just seven minutes on July 29, even though his keys were securely stored in a safety deposit box and had never been connected to the internet. "Perhaps the hardest part about this is that I did everything right," he expressed, adding that he is now filing reports with law enforcement and the Ontario Securities Commission.
