At least 1,596 Bitcoin has been stolen from about 7,300 Coldcard wallet addresses in an exploit tied to a firmware flaw dating back to March 2021. Three major attack waves and 14 smaller incidents have been confirmed, and a possible fourth wave could push the total to 2,055 BTC — worth roughly $130 million at current prices. Galaxy Research is helping victims trace their funds, and the firm has shared identified addresses with U.S. law enforcement, exchanges, and blockchain investigation outfits.
How the exploit worked
The vulnerability is in Coldcard firmware released in March 2021. A coding error caused some devices to generate recovery seeds using a weaker software-based process instead of the hardware random-number generator. That made the seeds predictable — and exploitable. Coinkite, the company behind Coldcard, has since urged all users to install the security update, create a new seed, and transfer their Bitcoin. But the patch only prevents creation of new weak seeds; it does nothing for wallets that already have a weak seed.
The aftermath: tracing the stolen Bitcoin
About 90% of the stolen Bitcoin hasn't moved. Coins from the first three waves remain at the initial attacker-controlled addresses, which Galaxy Research has flagged. At least 73 victims have contacted the firm for help. The number of attackers could be 15 or more, each exploiting the same vulnerability. Galaxy has shared its address list with U.S. law enforcement, major exchanges, and blockchain forensics firms — a move that could help freeze or recover funds if the attackers try to cash out.
Bitcoin network activity jumps
The Coldcard crisis appears to have jolted the Bitcoin network. Active addresses hit 712,000 over the past seven days — the highest in three months. Transactions worth more than $100,000 reached 61,800 in the same period, a five-month high. CryptoQuant said the exploit was the main catalyst. Smaller transactions also surged: those valued below $100,000 hit $3.2 billion, the highest since November 2024. The mempool swelled from about 33,000 to 96,000 pending transactions, the most since June 20. Long-term holders moved 406,000 BTC on a 30-day basis as of Aug. 3, up from 269,000 before the exploit — the highest level since January. Exchange inflows from smaller holders hit their highest since Feb. 6. Total exchange reserves rose by about 17,500 BTC between July 28 and Aug. 3, with Binance accounting for roughly 51% of that increase. The inflows don't necessarily mean holders intend to sell; some deposits could be temporary custody arrangements.
What comes next
A fourth attack wave remains unconfirmed. If it materializes, the total stolen could climb to 2,055 BTC. Galaxy Research continues to monitor the attacker-controlled addresses for any movement. The bigger question: how many Coldcard users still have weak seeds on their devices? Coinkite's patch can't retroactively fix those wallets — only a full seed migration can. The full extent of the vulnerability remains unknown.




