Galaxy Digital: Coldcard Losses Blow Past $100M After 1,596 BTC Stolen Across 17 Attack Waves

04-Aug-2026 Crypto Economy

TL;DR

  • Galaxy Research identified 1,596 BTC stolen from 7,300 addresses across three confirmed waves linked to a vulnerability in Coldcard.
  • An unconfirmed fourth wave would bring the total to 2,055 BTC, equivalent to approximately $130 million in losses.
  • 90% of the stolen funds have not moved, and Galaxy is collaborating with U.S. federal agencies to track the compromised addresses.

A hardware vulnerability in Coldcard could have resulted in losses of up to $130 million in bitcoin, according to an analysis published Monday by Galaxy Research.

The firm identified 1,596 BTC stolen from 7,300 addresses across three confirmed waves of attacks, plus 14 incidents of smaller scale. The root of the problem lies in a flaw affecting seeds generated on the Mk3, Mk4 and Mk5 models of Coinkite, as well as certain firmware versions of the Coldcard Q.

The first exploit reports emerged on July 30 in what appeared to be a programmatic and automated sweep, possibly assisted by large language models. Coinkite responded with emergency firmware updates for all affected models and confirmed that it destroyed the remaining vulnerable inventory.

Coldcard Could Face a Fourth Wave of Attacks

Galaxy Research warns that losses could be even greater if a fourth wave of attacks is confirmed. “While we have identified a potential Wave 4, we have not yet received specific confirmation from victims of their inclusion in this wave,” the firm stated. “Including it would bring the total to 2,055 BTC ($130 million).

The company indicated it has medium-high confidence that this fourth wave is substantially composed of a single attacker, although the lack of victim confirmation prevents closing the analysis. Alex Thorn, Galaxy’s head of research, flagged the existence of this wave after detecting that the transaction pattern matched that of the previous waves.

Galaxy digital Coldcard

Frozen Funds and Collaboration with Authorities

A crucial detail is that 90% of the stolen funds have not been moved, and all assets corresponding to waves 1, 2 and 3 remain static. Galaxy confirmed it is actively cooperating with federal agencies in the United States, exchanges and cybersecurity research groups, to whom it provides the confirmed addresses of attackers and victims.

The firm urged all Coldcard users to migrate their funds to a secure address and to generate a new seed on a device without the vulnerability, warning that the attack is ongoing and that new opportunistic hackers could join in.

Also read: Bitmine’s $10.9B Ethereum Bet: 5% Supply Goal Within Reach
WHAT'S YOUR OPINION?
Related News