Galaxy flags Coldcard-linked BTC thefts could near $130M as a suspected fourth wave emerges
Galaxy Research says Bitcoin stolen in the Coldcard-linked breach may approach $130M if a yet-unconfirmed fourth wave is included, underscoring risks in self-custody security.

Because Bitcoin
August 4, 2026
The running tally of Bitcoin drained in the Coldcard-linked incident appears far from settled. Galaxy Research said on X that losses could climb toward $130 million if a yet-unconfirmed fourth wave of attacks is ultimately validated. That single data point is doing a lot of work: it suggests the campaign is layered, patient, and designed to hide in user behavior as much as in code.
The critical lens here is the cadence of “waves.” Well-orchestrated wallet-targeted campaigns often exploit the same psychological edges they do technical ones. Attackers pace activity to create false resolution—users breathe out after the first spike, vendors issue guidance, then fresh outflows resume. By staggering pushes, adversaries fragment community forensics, increase mixing opportunities on-chain, and reduce the probability that any one signature gets definitively attributed. In practical terms, preliminary on-chain estimates frequently undercount because: - funds hop through peel chains and cross-ecosystem bridges over days or weeks, - victims discover losses asynchronously (especially with infrequent cold storage checks), - and attribution heuristics lag when UTXOs commingle before clustering converges.
If a fourth wave is indeed in play, it would fit a pattern where the attack surface isn’t a single flaw but a workflow. Bitcoin self-custody hardens at the edges yet can remain brittle in the middle: firmware provenance, host-computer infections during PSBT signing, unsafe QR/USB flows, seed-phrase handling, and recovery practices are common fault lines. You rarely need an exotic zero-day when everyday operational shortcuts exist.
This is where the business implications for hardware wallets become real. Trust in a device is rarely about perfect code; it’s about clear threat models, fast incident response, and product architectures that degrade gracefully under compromise. Vendors that ship opinionated defaults—aggressive address verification, sane rate limits, robust anti-rollback, deterministic build reproducibility, transparent supply chain attestations—tend to fare better when the market is stressed. For Bitcoin-first users, diversified custody setups (e.g., multi-vendor multisig, stateless signers, dedicated air-gapped flows) can reduce correlated risk without wrecking usability, but they require discipline that many postpone until it’s too late.
Disclosure choices matter as well. Communication that is precise about scope, honest about unknowns, and pairs technical updates with concrete user actions tends to stop secondary losses. Hand-waving or blame-shifting rarely does. The ethical center of gravity in these events sits with victims: they deserve rapid guidance, tooling to triage exposure, and a clear pathway to remediation—even while investigations remain ongoing.
If you think you might be exposed, simple guardrails go a long way while details firm up: - pause outbound transactions from potentially affected setups and verify receive addresses on-device, - rederive wallets on clean, freshly initialized hardware and rotate to new seeds where feasible, - favor PSBT workflows that avoid untrusted hosts; if you must, quarantine and verify binaries rigorously, - consolidate longer-term holdings into a segregated, vendor-diversified multisig you control.
None of this asserts fault or finality. It recognizes that campaigns arriving in waves are engineered to stretch attention and exhaust diligence. The $130 million figure Galaxy floated on X isn’t an endpoint; it is a reminder that adversaries optimize for opacity and time. Precision takes time, but drift favors the attacker. Tighten processes now, let attributions catch up later.