Coldcard Bitcoin Attack Estimate Climbs to $88.6M as New Wallets Surface

Coldcard Bitcoin Attack Estimate Climbs to $88.6M as New Wallets Surface

key insights

  • Weak entropy during wallet creation can undermine every security feature added later.
  • Blockchain analysis continues expanding the estimated scale as investigators identify related address clusters.
  • Firmware updates protect future wallets but cannot repair previously generated recovery phrases.

Coldcard entered a deeper security crisis after Galaxy Research identified a third suspected attack wave linked to wallets created with vulnerable firmware. The latest findings lifted estimated losses to 1,367.05 BTC, worth about $88.6 million, across 4,585 addresses and reinforced concerns over hardware wallet seed generation.

Galaxy Research published the updated estimate on Aug. 1 after tracing another 207.7294 BTC to addresses believed to share the same weakness. Although investigators classified the activity as suspected theft, the growing on-chain evidence suggests the scale extends well beyond initial estimates.

Early estimates expanded as investigators traced new clusters

The investigation began after researchers detected roughly 594 BTC leaving hundreds of single-signature wallets. At the time, estimated losses stood near $38 million, making the incident appear limited.

Further blockchain analysis changed that assessment. Galaxy later reconstructed a coordinated sweep that removed 1,082.65 BTC from 1,196 addresses within 41 minutes on July 30. The transactions were found in six consecutive Bitcoin blocks, indicating it was a well-organized affair and not a string of isolated compromises.

A second attack wave followed on July 31, draining another 76.16 BTC from 1,478 addresses. Researchers then uncovered a third cluster involving 207.7294 BTC across 1,912 additional wallets.

Together, those three waves raised the observed total to 1,367.05 BTC across 4,585 addresses. Galaxy emphasized that the figure represents an observed on-chain estimate and could change if more linked wallets emerge.

Metric                                         Reported figure

Estimated Bitcoin stolen          1,367.05 BTC

Estimated value                         $88.6 million

Total affected addresses           4,585

Third attack wave                      207.7294 BTC

First coordinated sweep          1,082.65 BTC

Investigation date                     Aug. 2, 2026

Firmware error weakened wallet security

The investigation traced the root cause to firmware released after a software integration change in March 2021. Instead of relying on the intended hardware random-number generator, affected devices generated wallet seeds through a deterministic software fallback.

That flaw significantly reduced seed randomness. Earlier Mk2 and Mk3 devices provided roughly 40 bits of effective entropy, while Mk4, Mk5 and Q models reached about 72 bits instead of the expected 128 bits.

Researchers explained that attackers could reproduce possible seed combinations offline before comparing derived public addresses against blockchain records. Consequently, wallets remained vulnerable even without malware, phishing attacks or stolen recovery phrases.

The issue also demonstrated that air-gapped storage cannot compensate for weak randomness during wallet creation. Once a predictable seed exists, later security protections cannot restore its original strength.

Security updates solve future risks but not existing wallets

Coinkite released firmware updates across affected product lines after confirming the vulnerability. The company also accepted responsibility for the software integration error and continues investigating the incident.

However, updated firmware protects only newly generated wallets. Existing recovery phrases created under vulnerable releases remain exposed because software updates cannot increase randomness after seed generation.

The company advised affected users to create entirely new wallets using corrected firmware. It also recommended verifying backup phrases, confirming receiving addresses and sending a small test transaction before transferring remaining balances.

Seeds created with at least 50 independent dice rolls remain outside the scope of this vulnerability. Likewise, TAPSIGNER, SATSCARD and OPENDIME products use different codebases and were not affected.

Broader implications extend beyond one wallet maker

The incident highlights a critical lesson for the cryptocurrency industry. Hardware isolation protects private keys only after secure generation, making randomness one of the most important foundations of wallet security.

Galaxy Research noted that nearly all Bitcoin linked to the suspected attacks remains unspent on-chain. That visibility allows investigators to monitor future movements while leaving open the possibility that additional address clusters could emerge.

At the same time, blockchain tracking may become more difficult if stolen funds eventually move through mixers, bridges or multiple intermediary wallets. Future transaction patterns could determine whether investigators maintain visibility into the stolen assets.

Conclusion

The Coldcard incident serves as a reminder of the importance of careful wallet generation to ensure many years of trusted security. Firmware updates will prevent new seeds from being created, but will not fix any vulnerable recovery phrases created during vulnerable releases. Even if the wallet is impacted, users will still need to transfer their own funds to newly generated seeds to remove the last hazard.

Galaxy Research is still monitoring on-chain activity, and there is a chance that there may be more tainted addresses to come. With most of the stolen Bitcoin still unmoved, investigators retain visibility into the funds for now. The case also reinforces a broader lesson for the crypto industry that secure key generation remains as critical as safeguarding private keys after they are created.

Brenda Mary

Brenda Mary is a cryptocurrency journalist, SEO analyst, and editor with over 3 years of experience in blockchain, digital assets, and crypto market analysis. She has contributed to leading platforms including Crypto.news, Cryptopolitan, The Coin Republic, and Analytics Insight.
At CoinRaftar, she covers crypto news, market trends, and Web3 developments, simplifying complex topics into clear, reader-friendly insights.
Bachelor’s in International Business Management, University of Nairobi.
https://www.linkedin.com/in/brenda-mary-248b2422b/

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top