
Galaxy Research reports that 87.3% of the 1,789.28 Bitcoin (worth $114.7M) stolen in the Coldcard hack remains unmoved, with most funds still in attacker-controlled addresses.
AI-generated summary
The Coldcard hack is one of the largest hardware wallet exploits, highlighting crypto security concerns.
The vast majority of Bitcoin stolen in the Coldcard hack remains unmoved, according to researchers tracking one of the largest hardware wallet exploits. Galaxy Research has attributed the theft of 1,789.28 Bitcoin from 8,865 addresses to the Coldcard hack, according to a Monday X post by Alex Thorn, Galaxy’s head of research. The funds were worth $114.7 million at the time of theft. Thorn said attackers have not spent 1,561 Bitcoin, or 87.3% of the attributed losses. The funds remain in attacker-controlled collection or holding addresses, including all Bitcoin stolen during the first three attack waves. Some Bitcoin stolen in later attacks has since moved through CoinJoin transactions, peel chains and other obfuscation methods, Thorn added. Source: Alex Thorn The latest tally draws partly on 221 victim reports covering 790.72 Bitcoin in losses, or 44.2% of the total Galaxy attributed to the hack. The median loss per report was 1.04272 Bitcoin, meaning more than half of the reported cases involved losses exceeding 1 Bitcoin. The largest stolen holdings remain visible onchain in attacker-controlled addresses. Galaxy has shared the identified attacker addresses with crypto exchanges, compliance companies and law enforcement in hopes that the funds can be frozen if they reach centralized intermediaries.
AI outlook — possibilities, not facts
Increased investment in crypto security research
Likely · Within months

Shipyard, a key maintainer of the InterPlanetary File System (IPFS), will end engineering and infrastructure operations on September 30 after Protocol Labs declined to renew funding, leaving several IPFS projects without dedicated support.

Ledger has released Ethereum app version 1.22.2 to patch a vulnerability that allowed malicious dApps to replace transaction data during signing. The flaw, identified by TestMachine and Ledger Donjon, affects multiple models including Ledger Flex, Nano X, and Stax.

BNB Smart Chain has launched its Pasteur hard fork, an upgrade designed to improve network security, bridge verification, and block capacity. The update integrates three BNB Evolution Proposals to streamline transaction processing and validator operations.

A Zilliqa Ledger application bug exposed 6,772 accounts and enabled the theft of 683.13 million ZIL. The flaw, which caused biased signatures, allowed attackers to reconstruct private keys. Zilliqa has paused legacy transactions as users migrate to Zilliqa EVM.

The anonymous AI model 'Ox Alpha' has gained significant attention for its high performance on coding benchmarks. Despite its viral popularity and endorsement by tech leaders, the developer remains unknown, with analysts pointing toward Zhipu AI as a likely source.

Draft EIP-8390 proposes removing Ethereum's 512-validator sync committee and Altair light-client interface, replacing them with offchain zero-knowledge proofs. The change aims to reduce annual consensus issuance by 33,800 ETH but lacks a defined replacement roadmap.