Coldcard Exploit Pauses After Draining 1,778 BTC, But Galaxy Sees Room for a Fourth Wave

Galaxy Research tallies 1,778 BTC (~$112M) stolen via a Coldcard seed flaw, with a possible fourth wave lifting losses to 2,417 BTC. Activity stopped after Aug 6; most funds remain unmoved.

Bitcoin
Cryptocurrency
Regulations
Economy
Because Bitcoin
Because Bitcoin

Because Bitcoin

August 14, 2026

The on-chain trail has quieted, but the damage keeps compounding. Galaxy Research now attributes at least 1,778 BTC—about $112 million—to a Coldcard seed-recreation exploit that started July 30. Confirmed attacker activity stopped after August 6 across three waves and dozens of smaller footprints, suggesting the obvious targets either migrated or were already emptied. Even so, Galaxy is tracking a potential fourth wave of 638.5 BTC that, if confirmed, would push total losses to 2,417 BTC (over $151.3 million at current prices).

Here’s the uncomfortable core: a 2021 firmware change quietly shifted seed generation from the hardware RNG to a software fallback, shrinking effective entropy from 128 bits to as low as 40. With a device’s serial and clock state, attackers could reconstruct seeds and sweep UTXOs—no phishing kits, no malware, no hands-on device access. That is a governance failure more than a hacker triumph. When the randomness layer is altered without forceful disclosure and migration tooling, you don’t just introduce a bug—you rewrite user assumptions about threat models.

Galaxy’s attribution is built on owner-validated thefts and on-chain clustering. The first wave alone stripped 1,082.65 BTC from 1,195 addresses within minutes—about $70.5 million at the time. “Footprint E,” the largest single owner-confirmed cluster, lost 209.94 BTC (~$13.3 million) across 2,148 addresses. Wave 3 removed 208.24 BTC (~$13.0 million) from 1,912 addresses. Across the three proven waves and 41 smaller footprints, more than 5,200 addresses were drained.

The attackers’ posture looks patient rather than frantic. Of the confirmed 1,778+ BTC stolen, 1,531 BTC sits untouched in attacker-controlled wallets; roughly 246 BTC has moved, and about 65% of that flowed into CoinJoin rounds, with small drips reaching KuCoin and Jump Crypto. As of block 962,304 (data through Aug. 13), 1,499.27 BTC—nearly $93.9 million—remained unspent in their custody. That hoarding behavior often means two things: the adversary is confident reruns are available, and the perceived risk of rapid laundering outweighs the near-term benefit. It also keeps pressure on victims and investigators, who must assume further consolidation or peeling could resume with little warning.

The lull matters, but not for the reason people hope. Galaxy sees “no confirmed” attacker activity after Aug. 6 across the high-confidence clusters it has mapped. The more plausible read is that the vulnerable single-signature set has largely migrated—or been fully harvested. Galaxy has now spoken directly with more than 190 victims and continues to attribute losses as new reports surface. Their standing guidance remains blunt: if you still hold funds on a single-signature Coldcard, move to fresh addresses immediately.

Downstream effects are already visible. Roughly $15 billion in Bitcoin has shifted toward perceived safer custody since the episode, a rational if imperfect hedge against latent device risk. Competitors have warned that wallet security needs to evolve for AI-assisted vulnerability discovery, while several hardware firms are flagging a pickup in phishing that is piggybacking on user anxiety. Panic is a vector; attackers notice.

The strategic lesson isn’t about self-custody versus delegation; it’s about transparency and key ceremony discipline. Firmware that changes entropy sourcing should trigger loud, user-facing migrations, deterministic reproducibility checks, and easy paths to rotate seeds. Users gravitate to hardware precisely to freeze assumptions about randomness and isolation. Erode that, and you don’t just invite exploits—you fracture trust that takes years to rebuild.

If Galaxy’s unconfirmed fourth wave of 638.5 BTC materializes, the theft ledger moves to 2,417 BTC. Whether or not that proves out, the priority doesn’t change: rotate single-sig Coldcard seeds to new addresses, verify derivations, and treat any legacy device states from the 2021 entropy regression window as compromised until proven otherwise. The chain can wait; the attacker can too.