TL;DR
A hardware vulnerability in Coldcard could have resulted in losses of up to $130 million in bitcoin, according to an analysis published Monday by Galaxy Research.
The firm identified 1,596 BTC stolen from 7,300 addresses across three confirmed waves of attacks, plus 14 incidents of smaller scale. The root of the problem lies in a flaw affecting seeds generated on the Mk3, Mk4 and Mk5 models of Coinkite, as well as certain firmware versions of the Coldcard Q.
The first exploit reports emerged on July 30 in what appeared to be a programmatic and automated sweep, possibly assisted by large language models. Coinkite responded with emergency firmware updates for all affected models and confirmed that it destroyed the remaining vulnerable inventory.
LOSSES FROM COLDCARD HACK EXCEED $100M
High confidence 1,596 BTC has been stolen from ~7300 addresses across 3 confirmed waves + more 14 smaller incidents.
If we add suspected (but unconfirmed), the total balloons to $130m (2k BTC).
More in the thread below
pic.twitter.com/RAl3ib67qa
— Galaxy Research (@glxyresearch) August 3, 2026
Galaxy Research warns that losses could be even greater if a fourth wave of attacks is confirmed. “While we have identified a potential Wave 4, we have not yet received specific confirmation from victims of their inclusion in this wave,” the firm stated. “Including it would bring the total to 2,055 BTC ($130 million).“
The company indicated it has medium-high confidence that this fourth wave is substantially composed of a single attacker, although the lack of victim confirmation prevents closing the analysis. Alex Thorn, Galaxy’s head of research, flagged the existence of this wave after detecting that the transaction pattern matched that of the previous waves.

A crucial detail is that 90% of the stolen funds have not been moved, and all assets corresponding to waves 1, 2 and 3 remain static. Galaxy confirmed it is actively cooperating with federal agencies in the United States, exchanges and cybersecurity research groups, to whom it provides the confirmed addresses of attackers and victims.
The firm urged all Coldcard users to migrate their funds to a secure address and to generate a new seed on a device without the vulnerability, warning that the attack is ongoing and that new opportunistic hackers could join in.