Overview of Coldcard Wallet Exploits
The incidents of Bitcoin being stolen due to the significant exploit of Coldcard wallets appear to be diminishing, yet the total value of the cryptocurrency that has been taken is on the rise, hinting that the situation may still escalate. Galaxy Research, a prominent firm specializing in cryptocurrency analysis, has been closely monitoring this exploit since it began. As reported recently, this seed-recreation exploit associated with Coldcard wallets has resulted in the theft of over 1,778 Bitcoins, equivalent to about $112 million, with expectations that this figure might increase as investigations progress.
Details of the Exploit
According to Galaxy Research, the analysis is supported by strong confidence in their figures, attributed to confirmed thefts associated with named ownership since the onset of the attack on July 30. The firm noted in their updates via social platform X that the perpetrators have been active in exploiting vulnerabilities by recreating Coldcard-generated seeds from the early hours of July 30, 2026, and subsequently transferring the stolen funds.
Despite the lack of recorded activity post-August 6, this does not indicate the technique’s ineffectiveness. It is instead likely that the most accessible targets have already been compromised. An earlier firmware modification in 2021 inadvertently weakened Coldcard’s seed generation methodology, shifting dependence from its hardware random-number generator to a software alternative, drastically reducing key security from 128 bits down to approximately 40 bits. This vulnerability enabled attackers to reconstruct the wallet seeds using merely a device’s serial number and time data, facilitating coin transfers without needing phishing or malware strategies or direct physical access to the wallets.
Analysis of Theft Waves
Analysis by Galaxy reveals that the first recorded wave of theft, named Wave 1, accounted for 1,082.65 BTC looted within minutes from 1,195 different addresses, representing around $70.5 million at the time. The notable Footprint E, recognized as the largest confirmed cluster belonging to a single owner, lost 209.94 BTC totaling approximately $13.3 million spread across 2,148 addresses. Wave 3 similarly saw 208.24 BTC exploited, translating to close to $13 million from 1,912 addresses. Collectively, three identified waves and 41 additional smaller groups illustrate a total of over 5,200 compromised addresses.
As observed on August 13, data indicates that 1,499.27 BTC, which is about $93.9 million, remains idle in the hands of the attackers.
Current Status and Recommendations
Galaxy has managed to trace a small fraction of the stolen Bitcoin, with 174.97 BTC being observed entering coinjoin privacy mixes, while minor amounts have made their way to exchanges such as KuCoin and Jump Crypto. The firm has engaged with over 190 individuals who reported losses as part of their analysis. Noting the decline in active attack waves, Galaxy speculates this is due to the migration of vulnerable users or the majority of accessible funds already being stolen. They continue to advise any users still holding Bitcoin in single-signature Coldcard wallets to transfer their assets to new addresses to safeguard against potential losses.
Impact on the Cryptocurrency Market
This alarming breach has already prompted a significant shift, leading approximately $15 billion worth of Bitcoin into more secure storage solutions and eliciting warnings from Ledger about the necessity for wallet security to evolve in the face of advancements in AI-driven discovery tools. Other hardware wallet manufacturers have also observed a rise in phishing schemes capitalizing on the widespread concerns following this incident. Furthermore, Galaxy has identified a potential fourth wave involving 638.5 BTC, which, if confirmed, could inflate the total loss to 2,417 BTC, valued at over $151.3 million at current market rates.