Attackers have drained roughly $88.6 million in Bitcoin from Coldcard hardware wallets and are still going, with researchers at Galaxy warning that every vulnerable address will eventually be emptied.
Galaxy Research said on Saturday it had identified a third wave of thefts in which 207.73 BTC was swept, lifting its observed total to about 1,367 BTC across 4,585 addresses. The firm called the exploit ongoing.
If you hold Bitcoin in single-signature on a Coldcard with a seed phrase generated after March 2021, move it to a freshly generated seed. Coinkite has released a hotfix, and the hotfix does not protect a seed that already exists.
What went wrong
The vulnerability comes from a build error in Coinkite’s March 2021 firmware, which caused seed phrases to be generated with far too little randomness.
A seed phrase is meant to be effectively unguessable, drawn from a pool of possibilities so vast that searching it is impossible. The build error shrank that pool. Any private key derived from an affected seed became something an attacker could work out rather than something they would have to steal, which is why a device that never touched the internet offered no protection at all. Nothing was hacked. The keys were calculated.
Alex Thorn, Galaxy’s head of research, said the stolen coins had been dormant for an average of 3.18 years before being taken, meaning the victims were long-term holders who had done nothing wrong and had no reason to touch their wallets.
How the first wave unfolded
Galaxy traced the initial sweep to a 41-minute window between 1:10 and 1:51 UTC on 30 July, spanning blocks 960,183 to 960,191, in which 1,196 addresses lost 1,082.65 BTC worth about $70.2 million at the time.
That was roughly 30 hours before Coinkite published its first public security advisory. Whether the company could have moved faster is a question for the post-mortem, but the gap is on the record and it covers the largest single wave of losses so far.
An earlier preliminary estimate from AnchorWatch CEO Rob Hamilton had put the damage at 594.48 BTC, around $38 million, across roughly 500 transactions in a three-block range. Galaxy’s wider sweep more than doubled that, and the third wave has since taken the total higher again.
The initial transactions share a distinctive on-chain fingerprint, with identical fee rates of 30 satoshis per virtual byte and no change outputs. Galaxy said that pattern makes the first wave identifiable but warned that later attacks on Coldcard-generated addresses may not repeat it, which would make them considerably harder to spot.
The attack is still running
‘I continue to investigate and add new Coldcard victim and attacker addresses to our investigation database,’ Thorn posted to X. ‘The attack is ongoing — move your funds off Coldcard-generated addresses immediately if you have not done so.’
Thorn described the sweeps as deliberate and programmatic and said they were probably orchestrated using a large language model, though he presented that as an inference from the pattern rather than a confirmed finding. He warned that every single-signature Coldcard address created after the March 2021 update will eventually be drained, and that it is only a matter of time.
Galaxy said it has flagged roughly 600 suspected attacker addresses to federal investigators, compliance firms and cross-industry cyber investigators, and credited victims who shared transaction details with helping map the activity. The stolen funds from all three waves remain sitting in attacker addresses and have not moved.
Coinkite’s response
Coinkite co-founder Rodolfo Novak said in a post on Friday that the company takes responsibility for the firmware bug and is working to establish the full scope of the problem.
Novak confirmed Coinkite has released a hotfix removing the software fallback path at the centre of the vulnerability, but warned it does not protect seeds already generated on affected firmware. Users who created a seed on a vulnerable version were told to move their holdings to a newly generated one.
That distinction is the one to be clear about. Updating the device does not fix an existing wallet. The seed itself is the compromised object, and the only remedy is a new one.
‘I did everything right’
For some holders the warnings came too late. Canadian fitness coach Jonathan Goodman said in a post on X that 18.25 BTC, worth about CA$1.6 million, was swept from his wallets in a seven-minute window on 29 July. His keys were on a Coldcard kept in a safety deposit box that had never been connected to the internet.
‘Perhaps the hardest part about this is that I did everything right,’ Goodman wrote, adding that he is filing reports with police and the Ontario Securities Commission.
He had. Cold storage on a dedicated device, kept offline, in a bank vault, is close to the strongest setup an individual can build. It failed because the flaw was in the thing generating the keys, and no amount of physical security can defend against a key that can be calculated.
What this means for self-custody
The breach has driven an unusual reversal, with affected holders moving Bitcoin off self-custody and back onto centralised exchanges such as Coinbase and Binance, or onto freshly generated addresses. Security experts have urged caution during those transfers, and that caution matters, because moving funds in a hurry to a hastily created wallet is how people lose coins to the second mistake rather than the first.
There is a real argument buried in the panic, and it is narrower than it looks. Self-custody removes the risk that a company loses your money. It does not remove the risk that a piece of software generates your keys badly, and this incident is the clearest demonstration of that difference in years. A single-signature wallet has one point of failure, and here that point was the manufacturer’s random number generation. Multi-signature setups, which require keys from more than one device, are the standard answer to exactly this, and the losses documented so far are all single-signature.
Bitcoin traded around $63,256 on Sunday, up about 1% on the day, with no visible market reaction to the thefts. Galaxy said its investigation continues and further updates on estimated losses are expected as more victim addresses are identified.


