A security breach targeting Coldcard hardware wallets has resulted in the theft of more than 2,055 Bitcoin — roughly $130 million — from 7,300 addresses across three confirmed attack waves, with a possible fourth still under investigation. The incident, which became public on July 30, has driven Bitcoin's active addresses to a three-month high of 712,000 and whale transactions over $100,000 to a five-month peak of 61,800, as the network absorbs the fallout.
How the attacks worked
The attackers used automated, programmatic sweeps to drain wallets, and Galaxy Research suspects large language models may have assisted in the operation. Affected devices include Coldcard Mk3, Mk4, Mk5, and the Coldcard Q line. The exploit hit in at least three waves, and researchers warn a fourth wave could push total losses higher.
Coinkite's emergency response
Coinkite, the company behind Coldcard, released emergency firmware updates for all affected models and destroyed remaining vulnerable inventory. The company has not disclosed the root cause of the vulnerability, but the speed of the patch suggests the flaw was critical. Users are urged to update firmware immediately and move funds to new wallets.
Market and on-chain fallout
The surge in active addresses and large transactions reflects both victims moving funds and opportunistic traders reacting to the news. Santiment warned that Bitcoin volatility could remain elevated over the next few weeks. The stolen coins themselves are under heavy surveillance — the UTXOs are being tracked, making any attempt to cash out costly and risky.
What happens to the stolen Bitcoin
Trace Finance co-founder Leone Parise said the stolen coins 'cannot be easily converted to cash at face value.' The blockchain trail is too hot, and exchanges are likely to flag any deposits from the known addresses. For now, the attacker holds a fortune that is effectively frozen — a problem that may grow if a fourth wave materializes.




