When the first Coldcard sweeps were spotted on July 30, the figure was around 594 bitcoin. It has grown every day since.
Galaxy Research confirmed on Monday that thefts tied to the Coldcard hardware wallet have exceeded $100 million, with 1,596 BTC taken from roughly 7,300 addresses across three major attack waves plus 14 smaller incidents. Seventy-three victims have contacted its researchers, whose reports confirmed the first three waves and helped identify the smaller footprints, which Galaxy suspects may be opportunistic attackers exploiting the same flaw independently.
A suspected fourth wave began early Monday and was still running hours later. If confirmed, it would push the total to roughly 2,055 BTC, about $130 million. Galaxy has deliberately excluded it from the headline figure because no victim has verified it, assessing the likelihood as “medium-high” based on pattern matching alone. That distinction explains why loss estimates have varied across outlets, with CoinDesk reporting approximately $114 million and Fortune $116 million.
Galaxy’s head of research Alex Thorn published the fourth-wave warning without a victim report, choosing speed over confirmation while the transactions were still unconfirmed. That decision may have saved money.
The Window That Opened by Accident
The fourth wave differed from its predecessors in one significant respect, and it handed some victims a lifeline.
Unlike earlier sweeps, Monday’s transactions opted into replace-by-fee, a bitcoin feature allowing an unconfirmed transaction to be overwritten by a later one paying a higher fee. Thorn flagged that similar transactions were still sitting in the mempool with RBF enabled, meaning holders who checked their funds quickly and paid a high enough fee could potentially outbid the attacker and move their coins first.
It is a genuinely unusual situation: a race conducted in public, in real time, between a thief and their victim, decided by whoever pays more. Whether many holders acted fast enough is not yet clear.
Two other patterns have emerged from the forensics. None of the addresses hit in the first three waves used multisignature setups, suggesting the flaw affects single-key Coldcard seeds specifically. And the fourth wave sent funds to previously unused addresses, making them harder to trace than in earlier sweeps.
Roughly 90% of the stolen bitcoin has not moved. Galaxy reads that as attackers preparing to launder rather than a failure to act, though some funds have already been swept into second-hop addresses. The stillness is also an opportunity: the coins remain traceable, and Galaxy has supplied attacker and victim addresses to law enforcement and exchanges while launching a $5 million security fund.
An On-Chain Aftershock
The most striking secondary effect is what happened to bitcoin’s base layer as tens of thousands of people rushed to secure their coins.
Volume for sub-1 BTC transfers reached 39,600 BTC in a single day, the highest daily volume of small-denomination transfers since the FTX collapse in 2022. That is the visible footprint of a mass migration: users sweeping funds from potentially compromised seeds into freshly generated wallets, or handing them to centralised exchanges rather than trusting their own setup again.
The migration produced localised fee spikes as the network absorbed the surge, and it carries an uncomfortable irony. A catastrophic failure in a self-custody product has driven a measurable flow of bitcoin toward custodians, the precise counterparties self-custody exists to avoid.
The Certification Gap
Kraken’s chief security officer Nick Percoco called the incident a wake-up call for the entire hardware wallet industry, and his specific criticism is the most instructive commentary to emerge so far.
Coldcard’s Mk4, Mk5 and Q models ship with certified secure elements. Those seeds still came out at roughly 72 bits of entropy rather than the 128-bit standard, because the certification covered the component while nobody verified which code path actually ran. A March 2021 firmware build had routed seed generation to a predictable software randomiser instead of the chip’s hardware one, and the certified hardware sat there unused.
That gap between a certified part and a verified system is the lesson worth carrying beyond Coldcard. A security audit that validates a chip tells you nothing about whether the firmware calls it.
Coinkite has responded aggressively since the flaw surfaced. It released emergency firmware for every affected model, halted shipments, and destroyed all remaining devices carrying the flawed firmware. Its guidance remains unchanged and critical: anyone who generated a seed on the affected software must move funds to a wallet created with an entirely fresh seed. Patching the firmware does not repair a seed that was already generated weakly.
What It Means
Bitcoin traded near $62,600 on Monday and around $63,600 on Tuesday, a restrained reaction given the scale of losses and the erosion of confidence in cold storage. The market has largely treated this as a product failure rather than a protocol one, which is accurate: the bitcoin network functioned exactly as designed throughout.
The harder question is what it does to self-custody adoption. The industry has spent a decade telling people that hardware wallets are the responsible choice, and that advice remains directionally correct. But this incident exposed that the advice was incomplete. Users were told to verify their device was air-gapped and their backup was secure. Nobody told them to verify the quality of the randomness their device produced at setup, and almost nobody could have.
The practical takeaways are narrow but real. Where a device offers user-supplied entropy through dice rolls, use it; Coldcard owners who rolled 50 or more dice were untouched by all four waves. Where multisig is feasible, it added meaningful protection here. And treat certifications as covering components rather than whole systems.
Losses have grown every day for five days, roughly 90% of the stolen coins are still sitting untouched, and the fourth wave remains unconfirmed. This is not a closed story. Anyone who generated a Coldcard seed on firmware from 2021 onward should assume exposure and act accordingly, because waiting to find out has already proven expensive for more than 7,000 addresses.
FAQ
How much has been stolen so far?
Galaxy Research confirmed 1,596 BTC, worth over $100 million, taken from roughly 7,300 addresses across three major attack waves plus 14 smaller incidents, verified through 73 victim reports and on-chain analysis. A suspected fourth wave that began August 3 could push the total to about 2,055 BTC, around $130 million, but Galaxy has excluded it from the confirmed figure because no victim has verified it. Other outlets have reported estimates between $114 million and $116 million.
Can victims still recover their coins?
Some may. The fourth wave’s transactions opted into replace-by-fee, meaning holders who spotted their coins in the mempool before confirmation could pay a higher fee to outbid the attacker and move funds first. More broadly, roughly 90% of the stolen bitcoin has not moved from the attacker’s addresses, leaving it traceable. Galaxy has shared attacker and victim addresses with law enforcement and exchanges, and launched a $5 million security fund.
What should Coldcard owners do now?
Coinkite has released emergency firmware for all affected models, halted shipments and destroyed remaining devices carrying the flawed build. Critically, updating firmware does not fix a seed generated on the vulnerable software. Owners must create an entirely new seed on patched firmware and move funds to addresses derived from it. Seeds generated using 50 or more user dice rolls carried genuine entropy and were not affected, and multisignature setups were not hit in the first three waves.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any investment decisions.


















