key insights
- Weak entropy during wallet creation can undermine every security feature added later.
- Blockchain analysis continues expanding the estimated scale as investigators identify related address clusters.
- Firmware updates protect future wallets but cannot repair previously generated recovery phrases.
Coldcard entered a deeper security crisis after Galaxy Research identified a third suspected attack wave linked to wallets created with vulnerable firmware. The latest findings lifted estimated losses to 1,367.05 BTC, worth about $88.6 million, across 4,585 addresses and reinforced concerns over hardware wallet seed generation.
Galaxy Research published the updated estimate on Aug. 1 after tracing another 207.7294 BTC to addresses believed to share the same weakness. Although investigators classified the activity as suspected theft, the growing on-chain evidence suggests the scale extends well beyond initial estimates.
We identified a 2nd wave of sweeps likely attributed to the same Coldcard hacker as the wave we described in the thread below.
We are now tracking 1,158.81 BTC stolen from 2,673 addresses and held unspent across 7 attacker addresses.
Updates to our analysis from yesterday 👇 https://t.co/UIDiRvw64K pic.twitter.com/2PHAWto9gx
— Galaxy Research (@glxyresearch) August 1, 2026
Early estimates expanded as investigators traced new clusters
The investigation began after researchers detected roughly 594 BTC leaving hundreds of single-signature wallets. At the time, estimated losses stood near $38 million, making the incident appear limited.
Further blockchain analysis changed that assessment. Galaxy later reconstructed a coordinated sweep that removed 1,082.65 BTC from 1,196 addresses within 41 minutes on July 30. The transactions were found in six consecutive Bitcoin blocks, indicating it was a well-organized affair and not a string of isolated compromises.

A second attack wave followed on July 31, draining another 76.16 BTC from 1,478 addresses. Researchers then uncovered a third cluster involving 207.7294 BTC across 1,912 additional wallets.
Together, those three waves raised the observed total to 1,367.05 BTC across 4,585 addresses. Galaxy emphasized that the figure represents an observed on-chain estimate and could change if more linked wallets emerge.
Metric Reported figure
Estimated Bitcoin stolen 1,367.05 BTC
Estimated value $88.6 million
Total affected addresses 4,585
Third attack wave 207.7294 BTC
First coordinated sweep 1,082.65 BTC
Investigation date Aug. 2, 2026
Firmware error weakened wallet security
The investigation traced the root cause to firmware released after a software integration change in March 2021. Instead of relying on the intended hardware random-number generator, affected devices generated wallet seeds through a deterministic software fallback.
That flaw significantly reduced seed randomness. Earlier Mk2 and Mk3 devices provided roughly 40 bits of effective entropy, while Mk4, Mk5 and Q models reached about 72 bits instead of the expected 128 bits.
Researchers explained that attackers could reproduce possible seed combinations offline before comparing derived public addresses against blockchain records. Consequently, wallets remained vulnerable even without malware, phishing attacks or stolen recovery phrases.
The issue also demonstrated that air-gapped storage cannot compensate for weak randomness during wallet creation. Once a predictable seed exists, later security protections cannot restore its original strength.
Security updates solve future risks but not existing wallets
Coinkite released firmware updates across affected product lines after confirming the vulnerability. The company also accepted responsibility for the software integration error and continues investigating the incident.
However, updated firmware protects only newly generated wallets. Existing recovery phrases created under vulnerable releases remain exposed because software updates cannot increase randomness after seed generation.
The company advised affected users to create entirely new wallets using corrected firmware. It also recommended verifying backup phrases, confirming receiving addresses and sending a small test transaction before transferring remaining balances.
Seeds created with at least 50 independent dice rolls remain outside the scope of this vulnerability. Likewise, TAPSIGNER, SATSCARD and OPENDIME products use different codebases and were not affected.
Broader implications extend beyond one wallet maker
The incident highlights a critical lesson for the cryptocurrency industry. Hardware isolation protects private keys only after secure generation, making randomness one of the most important foundations of wallet security.
Galaxy Research noted that nearly all Bitcoin linked to the suspected attacks remains unspent on-chain. That visibility allows investigators to monitor future movements while leaving open the possibility that additional address clusters could emerge.
At the same time, blockchain tracking may become more difficult if stolen funds eventually move through mixers, bridges or multiple intermediary wallets. Future transaction patterns could determine whether investigators maintain visibility into the stolen assets.
Conclusion
The Coldcard incident serves as a reminder of the importance of careful wallet generation to ensure many years of trusted security. Firmware updates will prevent new seeds from being created, but will not fix any vulnerable recovery phrases created during vulnerable releases. Even if the wallet is impacted, users will still need to transfer their own funds to newly generated seeds to remove the last hazard.
Galaxy Research is still monitoring on-chain activity, and there is a chance that there may be more tainted addresses to come. With most of the stolen Bitcoin still unmoved, investigators retain visibility into the funds for now. The case also reinforces a broader lesson for the crypto industry that secure key generation remains as critical as safeguarding private keys after they are created.









