Close Menu
AlexaBlockchain
  • News
  • Press Releases
    • Submit Press Release
  • Adoption
  • Funding
  • Interview
  • Policy
  • Explained
    • Bitcoin Halving 2024: Will it Trigger the Next Bull Run?
    • Everything You Wanted to Know About Bitcoin But Were Too Afraid To Ask
    • Cryptocurrency: what makes it so popular?
    • Top Five Crypto Scams And How To Avoid Them
    • Cloud Mining Explained
    • What are NFTs?
    • What is a Web3 Browser?
    • How To Build High Quality Crypto Backlinks
  • About
  • Advertise
  • Trending
    • #BitcoinHalving
    • #CloudMining
    • #Web3.0
    • #Metaverse
    • #NFTs
    • #PlayToEarn
    • #DeFi
    • #BlockchainTechnology
    • #Bitcoin
    • #Cryptocurrency
    • #DigitalAssets
Facebook X (Twitter) Instagram
Tuesday, August 4
  • Advertise
  • Crypto PR
  • Partner
  • Submit Press Release
  • Contact Us
X (Twitter) Facebook LinkedIn Instagram
AlexaBlockchain
Banner
  • News
  • Press Releases
    • Submit Press Release
  • Adoption
  • Funding
  • Interview
  • Policy
  • Explained
    • Bitcoin Halving 2024: Will it Trigger the Next Bull Run?
    • Everything You Wanted to Know About Bitcoin But Were Too Afraid To Ask
    • Cryptocurrency: what makes it so popular?
    • Top Five Crypto Scams And How To Avoid Them
    • Cloud Mining Explained
    • What are NFTs?
    • What is a Web3 Browser?
    • How To Build High Quality Crypto Backlinks
  • About
  • Advertise
  • Trending
    • #BitcoinHalving
    • #CloudMining
    • #Web3.0
    • #Metaverse
    • #NFTs
    • #PlayToEarn
    • #DeFi
    • #BlockchainTechnology
    • #Bitcoin
    • #Cryptocurrency
    • #DigitalAssets
AlexaBlockchain
You are at:Home » COLDCARD Bitcoin Theft Tops $102M as Investigators Track at Least 15 Attacker Patterns
Featured

COLDCARD Bitcoin Theft Tops $102M as Investigators Track at Least 15 Attacker Patterns

Galaxy Research has linked at least 1,596 BTC to the COLDCARD wallet flaw, as investigators track 15 attacker patterns and warn users to replace affected seeds.
Ravi KumarBy Ravi KumarAugust 4, 2026Updated:August 4, 2026No Comments13 Mins Read
Twitter Facebook LinkedIn Reddit Email WhatsApp
COLDCARD Bitcoin Theft Tops $102M as Investigators Track at Least 15 Attacker Patterns
COLDCARD Bitcoin Theft Tops $102M as Investigators Track at Least 15 Attacker Patterns. Image Credit: COLDCARD
Share
Twitter Facebook LinkedIn Pinterest Reddit Telegram Email WhatsApp
  • Galaxy Research has linked at least 1,596 BTC, worth over $102 million, to a flaw in COLDCARD wallet seed generation.
  • Investigators are tracking at least 15 attacker patterns, while a larger suspected set approaches 2,055 BTC.

A vulnerability in COLDCARD hardware wallets has been linked to the theft of at least 1,596 Bitcoin, pushing the estimated value of confirmed losses above $102 million (at current bitcoin price of $64,203).

Galaxy Research’s latest investigation, published on Aug. 3, traced the high-confidence theft set across roughly 7,300 Bitcoin addresses. The activity includes three major theft waves and at least 14 smaller incidents reported or confirmed by affected owners.

Bitcoin was trading near $64,027 on Aug. 4, valuing the confirmed total at approximately $102.2 million.

A broader pool of suspected activity reaches approximately 2,054.9 BTC, worth around $131.6 million at the same price. However, that figure includes pattern-matched transactions and a possible fourth wave that had not been confirmed by affected owners.

It should not be described as 2,055 BTC of confirmed COLDCARD theft.

Galaxy’s category-level chart accounted for approximately 1,590.9 BTC, around 5 BTC below its latest headline figure. The difference appears to reflect new victim reports and continued classification while the investigation was being assembled.

The cleanest current estimate is therefore Galaxy’s high-confidence total of 1,596 BTC.

More From AlexaBlockchain

  • How To Keep Your Cryptocurrency Holdings Safe And Secure?
  • A Beginner’s Guide to Crypto Insurance

At least 15 attacker patterns identified

Alex Thorn, Galaxy’s head of firmwide research, said investigators have identified at least 15 distinct transaction patterns associated with exploitation of the COLDCARD weakness.

That does not necessarily mean 15 individual hackers have been identified.

Galaxy is separating attackers through their onchain behavior, including how funds are consolidated, divided, routed and held. One operator could use several patterns. A single pattern could also represent a coordinated group.

The number is important because the incident no longer resembles one attacker discovering a weakness and sweeping a narrow group of wallets.

It increasingly resembles an expanding race to identify and drain vulnerable seeds before their owners can move the funds.

One victim who reported losing less than one bitcoin helped investigators identify what Galaxy calls “Footprint O.” Thorn said the previously unidentified pattern had drained approximately 12 BTC from 126 addresses.

Small victim reports are therefore helping investigators uncover larger clusters.

Galaxy reportedly has direct contact with around 80 victims. Those reports are central to the investigation because the affected addresses are dispersed across Bitcoin’s blockchain.

Unlike an exchange hack, the thefts do not originate from one known treasury address.

Galaxy maintains a broader triage list containing possible victims and suspicious transactions. Activity is only added to its headline estimate when investigators consider the supporting evidence sufficiently strong, often after an owner confirms that specific addresses were generated using an affected device.

Three large waves moved 1,367 BTC

The three largest known theft waves moved approximately 1,367.05 BTC.

The first wave was detected on July 30. An attacker swept 1,196 Bitcoin addresses in around 41 minutes, taking 1,082.65 BTC worth approximately $70.2 million at the time.

Two additional waves subsequently raised the observed large-wave total to 1,367.05 BTC across 4,585 addresses.

Galaxy said the coins associated with those three waves remained parked at tracked holding addresses as of its latest investigation.

The movement patterns differed considerably.

Wave 1 consolidated the stolen bitcoin through a relatively small number of funnel addresses. That produced a more concentrated and readable transaction graph.

Wave 3 divided the bitcoin among hundreds of staging and holding addresses.

That fragmentation makes the flow harder to monitor. It may also give the attacker more options for moving smaller amounts through bridges, exchanges, gambling platforms or informal liquidity networks.

The smaller suspected operators have already shown different laundering behavior.

According to Thorn, some stolen funds have moved through peel chains, THORChain and offshore gambling platforms. A peel chain repeatedly removes smaller amounts from a larger balance, leaving the remainder in a newly created address.

The technique complicates attribution by generating a long series of transactions.

In one case involving gambling platform Duel, the platform reportedly identified a depositor linked to the incident. The bitcoin had already been withdrawn before the funds could be frozen.

Traced does not mean recovered

Galaxy has shared roughly 600 suspected attacker addresses with federal investigators, exchanges, compliance companies, cyber investigators and the Security Alliance, commonly known as SEAL.

No public seizure, arrest, return of funds or successful freeze has been announced.

That distinction matters.

Bitcoin’s public ledger allows investigators to follow transactions after a theft. However, visibility does not provide control over the coins.

The large-wave funds that remain stationary are traceable, but they have not been recovered. The attackers still control the private keys.

Recovery becomes more difficult when bitcoin reaches a service that does not cooperate with investigators, operates in a loosely regulated jurisdiction or allows funds to be exchanged without robust identity checks.

Cross-chain conversion also creates additional complications.

Moving BTC through THORChain, for example, may allow an attacker to obtain an asset on another blockchain without depositing the bitcoin directly at a centralized exchange.

Investigators can still follow the transaction trail, but the process requires coordination across networks, analytics providers and service operators.

A deterministic fallback weakened wallet seeds

The underlying failure was not a break in Bitcoin’s cryptography.

It was a failure in the process used by affected COLDCARD firmware to create private keys.

Hardware wallets normally generate wallet seeds using highly unpredictable information supplied by a hardware random-number generator. The resulting recovery words control the private keys and therefore the bitcoin.

In the affected COLDCARD firmware, a configuration and software interaction caused seed generation to enter a deterministic MicroPython pseudorandom-number-generator fallback rather than using the expected hardware randomness.

Block’s Bitcoin Engineering and Security teams independently traced the problem after reports of active theft began appearing on July 30. Block said the vulnerability could allow an attacker to recreate candidate output streams under certain assumptions about a device’s identifier, timer state and earlier random-number-generator calls.

An attacker could generate possible seeds offline, derive the corresponding Bitcoin addresses and compare them with publicly visible addresses holding funds.

No physical access to the victim’s hardware wallet would necessarily be required.

The vulnerability was introduced after COLDCARD moved wallet-generation operations to a library called libNgU in March 2021. Block’s technical timeline shows that the vulnerable path was present in firmware version 4.0.0, while additional reseeding behavior was introduced for the Mk4 in 2022.

Coinkite described the cause as a complex chain of bugs that prevented the hardware random-number generator from contributing the intended randomness.

In simple terms, Bitcoin’s private-key system remained intact.

Some private keys were simply created from a much smaller range of possibilities than their owners expected.

Mk2 and Mk3 seeds face the highest risk

The most severely exposed seeds were generated on COLDCARD Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9.

Coinkite estimates that the affected Mk3 process may provide roughly 40 bits of effective search space under its assumptions. That is drastically weaker than the 128-bit target associated with a properly generated 12-word BIP-39 seed.

Later models received additional entropy from secure elements, reducing the severity but not eliminating the problem.

Coinkite said seeds generated on the Mk4 and Mk5 before firmware version 5.6.0, or on the COLDCARD Q before version 1.5.0Q, may contain approximately 72 bits of entropy rather than the intended 128 bits.

The affected firmware version is the version used when the seed was created.

Installing safe firmware today does not retroactively strengthen an old seed.

Restoring the same recovery words on a new COLDCARD, another hardware wallet or a software wallet also does not solve the problem. The vulnerability follows the seed words because those words encode the weakly generated private-key material.

Coinkite has released fixed firmware for each affected product line. However, the company says owners must generate an entirely new seed after installing the corrected firmware and transfer their funds to addresses controlled by that new seed.

Does this undermine the hardware-wallet safety narrative?

The incident will test one of the crypto industry’s most persistent security messages: that hardware wallets are safer than exchanges or internet-connected software wallets.

That message remains broadly defensible, but it needs qualification.

A hardware wallet isolates private keys from everyday laptops, browsers and smartphones. This can reduce exposure to malware, remote-access tools, phishing sites and compromised wallet extensions.

However, a hardware wallet is not automatically secure simply because the key is stored offline.

Its security also depends on firmware quality, random-number generation, supply-chain integrity, signing-screen accuracy, update procedures and how the owner creates and backs up the seed.

The COLDCARD incident exposes a particularly damaging failure because it affected the point at which the wallet’s core secret was born.

Air-gapped signing, secure elements and offline storage cannot protect a key that an attacker can recreate through a reduced search space.

The case therefore does not prove that software wallets or exchanges are safer.

It shows that “hardware wallet” is a product category, not a security guarantee.

The Bybit theft in February 2025 provided another warning about that distinction. Attackers stole $1.5 billion in Ether during a transfer involving an exchange cold wallet, making it the largest publicly reported crypto theft at the time. Investigators said the compromise manipulated the signing process rather than breaking Ethereum’s underlying cryptography.

Both incidents involved systems generally described as offline or cold storage.

The weaknesses were different. Bybit faced an institutional signing and operational-security compromise, while COLDCARD users were exposed through defective seed generation.

In each case, the protective label concealed a more complicated security stack.

Crypto exploits remained large in 2025 and 2026

The COLDCARD losses add to two years of major infrastructure, wallet and protocol compromises.

Bybit’s $1.5 billion theft dominated 2025. The incident also showed how one compromised workflow could bypass multiple institutional controls attached to a cold-wallet transfer.

Cetus, a decentralized exchange on the Sui network, suffered an exploit of approximately $220 million in May 2025. The incident contributed to $2.5 billion in crypto hack and scam losses during the first half of that year, according to CertiK.

Indian exchange CoinDCX disclosed the theft of approximately $44 million from an internal operational account in July 2025. The exchange said the stolen USDT was routed through several hops before reaching two principal wallets.

The attacks continued in 2026.

In April, an exploit involving KelpDAO and LayerZero infrastructure drained approximately $290 million in rsETH. Galaxy described it as the largest DeFi exploit of 2026 at the time, with knock-on effects across Aave lending markets.

Ostium subsequently lost around $24 million in a July exploit, according to Galaxy’s research index.

The incidents span different failure modes: compromised institutional signing, faulty smart contracts, operational-account breaches, bridge vulnerabilities and weak private-key generation.

The common theme is that attackers increasingly target the infrastructure surrounding cryptography rather than attempting to break the cryptographic algorithms themselves.

What COLDCARD owners should do

Users who generated a seed on an affected COLDCARD should not assume that installing an update is sufficient.

Coinkite recommends installing the fixed firmware for the applicable device before generating any replacement seed. The corrected versions include 4.2.0 or later for Mk2 and Mk3, 5.6.0 or later for standard Mk4 and Mk5 devices, and 1.5.0Q or later for the standard Q release. Separate fixed versions apply to the Edge firmware track.

Owners should then create a completely new seed.

They should record and verify the new backup, confirm the wallet fingerprint and verify a receiving address directly on the hardware-wallet screen.

A small test transaction should be sent first. The remaining balance should only be moved after the test transaction has arrived and the new wallet can be restored successfully.

The old seed backup should not be destroyed until the entire migration has been confirmed.

Users should never enter their recovery words into a website claiming to test whether a seed is vulnerable. Attackers are likely to exploit the public warning through fake migration tools, support accounts and phishing pages.

The COLDCARD PIN is also not the same as a BIP-39 passphrase.

Coinkite says a strong, unique and separately stored BIP-39 passphrase can create an additional barrier. However, a weak, reused or predictable passphrase may be guessed, and even a strong passphrase does not repair the affected seed.

Seeds created with at least 50 fair, independent and private dice rolls may not be exposed to this specific randomness failure alone. Users who do not clearly remember how the seed was created should treat it as potentially affected and migrate.

Larger holders should also reconsider reliance on one seed and one manufacturer.

A properly configured multisignature wallet can reduce the risk that one defective seed-generation process compromises all funds. However, Block warned that multisignature setups composed entirely of vulnerable COLDCARD devices may remain exposed. A secure quorum must include independently generated keys that are not affected by the flaw.

An ongoing security incident

The COLDCARD theft has already crossed nine figures, but the final loss may take weeks or months to establish.

More vulnerable wallets may remain funded. Additional attackers may be scanning the blockchain for addresses derived from weak seeds. Some victims may never contact investigators or may not yet know why their coins disappeared.

The difference between Galaxy’s confirmed and suspected sets is therefore likely to remain important.

A transparent accounting should distinguish victim-confirmed thefts from transactions that merely resemble the known attacker patterns.

The investigation also leaves broader organizational questions for Coinkite and the hardware-wallet industry.

The vulnerable path existed in publicly available firmware for years. It was not detected before attackers apparently began using it at scale, despite open-source review and growing use of artificial intelligence for code auditing.

Coinkite said an AI model it used to review the firmware before the disclosure did not find the bug. The company has suggested that attackers may have used similar tools to inspect older code, although no public evidence has established exactly how the weakness was discovered.

The episode is therefore not only a warning about one wallet.

It is a warning about security claims built around individual features.

Offline storage, secure elements and open-source firmware can all improve safety. None of them replaces verified randomness, independent audits, cautious key generation and a migration plan when a foundational assumption fails.

The coins still sitting in attacker-controlled addresses remain visible.

They are not yet recovered, and the theft may not be over.

The above article “COLDCARD Bitcoin Theft Tops $102M as Investigators Track at Least 15 Attacker Patterns” was first published on AlexaBlockchain. Read the complete article here: https://alexablockchain.com/coldcard-bitcoin-theft-tops-102m-as-investigators-track-at-least-15-attacker-patterns/

Read Also: This is the First U.S.-Chartered Depository Bank to Offer Stablecoin Invoicing

Disclaimer: The information provided on AlexaBlockchain is for informational purposes only and does not constitute financial advice. Read complete disclaimer here.

Bitcoin Cybersecurity Galaxy Digital
Share. Twitter Facebook LinkedIn Reddit Pinterest Tumblr Telegram Email WhatsApp
Ravi Kumar
  • X (Twitter)
  • LinkedIn

Ravi is Founder and Chief Content Officer of AlexaBlockchain. He writes about everything at the cross-section of blockchain, crypto, AI, markets, and the economy. Ravi can be reached at ravi@alexablockchain.com

More AlexaBlockchain

Lombard Opens Bitcoin-Backed Credit Vault With Flow Traders as First Borrower

July 23, 2026

Bitget Blocks 150 Million Cyber Threats in Major Security Push

June 29, 2026

White House Holds CLARITY Act Meeting Today as DeFi Rules Face Scrutiny

June 10, 2026

Bitcoin Rebounds to 64K After Brutal Selloff as Fed Rate Cut Bets Fade and Saylor Strategy Concerns Ease

June 8, 2026

Bitcoin Slumps Toward $61,000 as Zcash Bug, ETF Outflows and Strategy Sale Deepen Crypto Rout

June 5, 2026

This New Bitcoin-Aligned Stablecoin Eyes $100T B2B Finance

April 28, 2026
Add A Comment

Comments are closed.

Don't Miss

COLDCARD Bitcoin Theft Tops $102M as Investigators Track at Least 15 Attacker Patterns

THG Opens Hedera and AI Product Suite to Partners as Agent Security Risks Mount

Crypto Marketplace Xyper Enables AI Agents To Earn On-chain As Content Creators

Bitget Taps Chainlink to Enable Daily Bitcoin Yield for Users

Trending Topics
  • Blockchain News
  • Blockchain Technology
  • Blockchain Platforms
  • Blockchain Regulation
  • Bitcoin News
  • Ethereum News
  • Ripple News
  • Tezos News
  • CBDC
  • NFTs
Featured Companies
  • Binance
  • Tech Mahindra
  • Huobi
  • Efforce
  • Future FinTech Group
  • SuburbanColors
  • Launchpool Labs
  • Lucky Crab Club
  • SIMBA Chain
  • Bulldog Law
Stay Updated
  • Events
  • Newsletters
  • Follow
  • Follow on Google News
  • Blockchain Directory
Get In Touch
  • Crypto PR
  • Advertise
  • Partner
  • About
  • Masthead
  • Careers
  • Write for Us
  • Submit Press Release
  • Submit Guest Post
  • Contact US
Copyright © 2026. AlexaBlockchain
  • About
  • Advertise
  • Crypto PR
  • Submit Press Release
  • Write for Us
  • Careers
  • Privacy Policy
  • Affiliate Disclosure
  • Disclaimer
  • Contact

Type above and press Enter to search. Press Esc to cancel.