Key Takeaways:
- Galaxy tracked 1,367 BTC swept from 4,585 addresses across three waves
- Exchanges added a net 11,163 BTC on July 31 as inflows spiked
- Galaxy is watching 293 vaults for the first outbound spend
Key Takeaways:

Coldcard-related bitcoin sweeps reached an estimated 1,367 BTC, or about $88.6 million, across three waves that drained 4,585 addresses, Galaxy Research disclosed on X.
Galaxy Research said its findings are preliminary and based entirely on publicly available Bitcoin blockchain data. A separate dashboard called Coldcard Sweep Watch placed the theft at 1,158.8480 BTC at 5 p.m. EDT Saturday.
The first wave was the largest, sweeping 1,082.65 BTC from 1,195 addresses in 41 minutes on July 30. A second operation collected 76.16 BTC from 1,478 addresses the following day. The third wave stretched from July 31 into Aug. 1 and drained roughly 208 BTC from 1,912 addresses.
The third operation did not look like a simple continuation of the first two. Waves 1 and 2 funneled funds through a small number of collector and holding addresses. Wave 3 instead sent victims' funds into 293 separate P2WSH vaults, a type of bitcoin address that can hide its spending conditions until the coins move.
The separate vaults make it harder for outside observers to group the funds together. Galaxy explained that the change could indicate that the original attacker rebuilt the operation after the first sweeps became public, or that another party found the same vulnerable pool of addresses. Blockchain records alone cannot determine which explanation is correct.
Galaxy connected the activity to a vulnerable Coinkite Coldcard firmware release shipped on March 17, 2021. None of the affected coins were created before that release, and the median victim address had remained inactive for about 3.5 years, matching the behavior expected from long-term cold storage. Block's security team traced the fault to a production config that bound seed generation to MicroPython's Yasmarang fallback instead of the STM32 hardware random number generator, with Coinkite estimating effective entropy at roughly 40 bits on the Mk3 and about 72 bits on the Mk4, Mk5 and Q. Coinkite shipped emergency firmware for every affected model on July 31, but installing it does not repair an existing seed.
As researchers mapped the suspected thefts, centralized cryptocurrency exchanges recorded a sharp increase in bitcoin deposits on July 31. Data shared by Sani of Timechainindex.com showed net exchange inflows of 11,163 BTC during the day.
River received an estimated 3,679 BTC, followed by Binance with 3,224 BTC, Kraken with 2,848 BTC, and OKX with 1,291 BTC. Centralized entities collectively received 15,205 BTC from unidentified addresses, lifting their reported holdings in a single day.
Large exchange inflows often attract attention because coins deposited at trading platforms may be prepared for sale, collateral, or internal custody transfers. The data does not establish that the July 31 deposits came from Coldcard users, attackers, or anyone responding directly to the incident. The timing is still notable — a security scare can prompt holders to reorganize storage, move coins to exchanges, or abandon wallet setups they no longer trust. It can also coincide with unrelated institutional transfers and exchange bookkeeping, making the inflow spike important but inconclusive.
A third development emerged as a large slew of addresses created between 2010 and 2017 began moving coins after nine to 16 years of inactivity, according to statistics collected from btcparser.com. Visible transactions from July 30 through Aug. 1 totaled about 306 BTC, including repeated transfers of 10 BTC and 30 BTC.
One address created July 2, 2010, moved an old coinbase transaction of over 50 BTC. Other transactions included 37.8 BTC from a 2014 address and a coordinated group of transfers from three wallets created on July 29, 2017. Those three wallets moved 37.5 BTC and two separate 30 BTC amounts in the same block.
The dormant activity cannot be tied to the Coldcard sweeps from the available data. Galaxy Research detailed that the suspected victims' coins were all created after the vulnerable firmware was released in 2021, while many of the newly active dormant wallets held bitcoin years before Coldcard existed. However, much like the exchange activity Sani reported, long-dormant bitcoin holders may be questioning their security setups and shifting funds to alternatives, including custodial services.
Galaxy Research is monitoring seven holding addresses from the first two waves and 293 vaults from the third. The first spend from those vaults could expose their scripts and reveal whether the same signing keys or spending structure appear across multiple addresses. At press time, BTC traded at $62,326 per coin, with Strike CEO Jack Mallers calling the incident one of the most serious bitcoin hacks on record.
This article is for informational purposes only and does not constitute investment advice.