Galaxy Research has confirmed 1,596 BTC stolen from roughly 7,300 addresses across three attack waves, with a suspected fourth wave potentially pushing total losses to 2,055 BTC, or nearly $130 million.
Galaxy Research has confirmed 1,596 BTC stolen from roughly 7,300 addresses across three attack waves, with a suspected fourth wave potentially pushing total losses to 2,055 BTC, or nearly $130 million.

Coldcard exploit losses reached 1,596 BTC across three attack waves, with a fourth suspected wave potentially pushing the total to 2,055 BTC, or $130 million.
Galaxy Research said in a post published Monday on X that it has identified 1,596 BTC stolen from 7,300 addresses across three confirmed waves of attacks, along with 14 smaller security incidents linked to the Coldcard seed-generation flaw.
The firm's estimate excludes a fourth suspected attack wave because it has not yet received enough confirmation from affected wallet owners. If the additional activity is validated, the total would rise to 2,055 BTC, valued at about $130 million at current prices. Earlier blockchain analysis from Galaxy had estimated roughly 1,815.75 BTC moving across four observed waves, but the firm stressed those figures came from on-chain analysis rather than confirmed victim reports.
The attacks stem from a vulnerability affecting seeds generated on Coldcard Mk2, Mk3, Mk4, Mk5 and Coldcard Q devices running vulnerable firmware. Coinkite disclosed last week that the flaw originated in March 2021 while integrating a new cryptographic library into its firmware. Instead of generating wallet seeds through the intended hardware-backed true random number generator, affected firmware mistakenly relied on a deterministic pseudo-random generator provided by MicroPython.
Galaxy said it has identified what it believes is a fourth coordinated wave of theft but is still waiting for victim confirmation before adding those addresses to its confirmed tally. Blockchain activity suggests the suspected fourth wave is "substantially comprised of" one attacker, giving analysts medium-high confidence in that assessment despite remaining uncertainty over affected wallets.
Alex Thorn, Galaxy's head of firmwide research, first flagged the potential fourth wave on Aug. 3 after identifying transaction patterns that closely matched the earlier attacks. His running estimate later rose to 448.7 BTC moving from 709 potential victim addresses, although Galaxy stressed that blockchain data alone cannot confirm every victim or determine whether a single operator carried out every theft.
Coinkite estimates that affected Mk2 and Mk3 devices may provide roughly 40 bits of effective entropy, while vulnerable Mk4, Mk5 and Coldcard Q models may generate about 72 bits instead of the intended 128 bits. Block's Bitcoin engineering and security team independently reached the same conclusion after reviewing the firmware.
Galaxy said investigators have been working with U.S. federal law enforcement agencies, cryptocurrency exchanges and cyber investigation groups by sharing confirmed attacker and victim addresses. Approximately 90 percent of the stolen Bitcoin remains untouched, and none of the coins stolen during the first three confirmed attack waves have moved since they were taken.
Attack activity accelerated to about 13.8 wallet sweeps per Bitcoin block during the fourth suspected wave, compared with roughly 0.3 sweeps per block before the incident. Most stolen balances were transferred to newly created addresses rather than one central collection wallet, while some funds later moved through second-hop transactions that complicated blockchain tracing.
Coinkite has released emergency firmware updates for every affected product, including version 4.2.0 for Mk2 and Mk3 devices, version 5.6.0 for Mk4 and Mk5, version 1.5.0Q for Coldcard Q, and Edge releases 6.6.0X and 6.6.0QX. The company has also destroyed all remaining inventory containing vulnerable firmware.
Galaxy warned that new attackers could attempt to exploit the same vulnerability while affected devices remain in use. Users who still control compromised wallets should generate entirely new wallet seeds on patched devices and migrate their funds, the firm said. Coinkite recommends verifying a receiving address, sending a small test transaction, and transferring the remaining balance only after confirming the test succeeds.
The incident marks one of the largest attacks ever targeting Bitcoin self-custody through cryptographic key generation rather than malware, phishing or exchange breaches. It has also highlighted a supply-chain risk: users who securely stored offline wallets for years remained vulnerable if the wallet was originally created with the affected firmware, regardless of whether the device was later updated.
This article is for informational purposes only and does not constitute investment advice.