
Galaxy Research reports that the Coldcard wallet exploit has drained over 1,778 BTC (≈ $112 million), with losses slowing but expected to rise further as attackers target remaining vulnerable wallets.
AI-generated summary
A 2021 firmware update in Coldcard wallets inadvertently weakened security, allowing attackers to recreate seeds and steal funds without physical access or malware.
Stolen Bitcoin losses from the massive Coldcard wallet exploit have begun to slow, but the total amount of BTC swiped continues to climb—and the worst may not be over just yet. That’s the latest from Galaxy Research, the crypto research firm that’s been tracking the exploit from the start. The company said Thursday that the Coldcard seed-recreation exploit has now drained more than 1,778 BTC—roughly $112 million—and the final figure will likely be higher. Galaxy said it has "very high confidence" in the tally, which counts confirmed, owner-attributed thefts since the attack opened on July 30, per its running thread on X. "Attackers have been executing this attack since at least early morning July 30, 2026, systematically recreating Coldcard-generated seeds and sweeping the funds onchain," Galaxy Research wrote. Among Galaxy's confirmed waves and footprints, none shows activity after August 6. That doesn’t mean the method stopped working. It means the easy targets are gone. What the chains show A 2021 firmware update quietly rerouted Coldcard's seed generation off its hardware random-number chip and onto a software stand-in, collapsing key strength from 128 bits to as low as 40. Attackers could rebuild seeds from a device's serial number and clock state, then sweep the coins without resorting to phishing or malware techniques and even without physical access to the actual devices. Galaxy's breakdown puts the largest proven wave—Wave 1—at 1,082.65 BTC pulled from 1,195 addresses in the opening minutes. That was roughly $70.5M worth of Bitcoin stolen at the time. Footprint E, the biggest single owner-confirmed cluster, took 209.94 BTC (roughly $13.3M) across 2,148 addresses; Wave 3 took 208.24 BTC (near $13.0M) from 1,912. Across three proven waves and 41 smaller footprints, the firm charts more than 5,200 drained addresses. As of block 962,304 (data Aug. 13), 1,499.27 BTC (nearly $93.9M) sat unspent in attackers’ hands. Of the thin slice Galaxy can trace to a final endpoint—174.97 BTC—most went into coinjoin privacy rounds, with small amounts reaching KuCoin and Jump Crypto. Galaxy has spoken to more than 190 victims directly to attribute losses. "The abatement in attack waves is likely because vulnerable users have migrated or most funds have already been drained," it wrote. The company repeats its advice: "If you still hold funds on a single-signature Coldcard wallet, you are advised to move your funds to new addresses." The episode has already pushed roughly $15 billion in Bitcoin to safer custody and drawn a warning from Ledger that wallet security has to adapt to AI-assisted discovery. Hardware-firm peers have also flagged a phishing surge riding the panic. Galaxy still carries a candidate fourth wave—638.5 BTC it hasn’t confirmed—that would lift the toll to 2,417 BTC, above $151.3 million by today’s prices.
AI outlook — possibilities, not facts
Further losses may occur if all vulnerable wallets are not secured promptly.
Likely · Within days

MANTRA Chain halted its mainnet on Aug. 21 after an attacker exploited an upstream dependency. Transactions, staking, and transfers are currently suspended while the team tests a security patch on the DuKong testnet before a coordinated restart.

Solana has successfully reduced its slot time to 350 milliseconds, down from 400ms, as part of a multi-stage plan to improve network latency. The update, approved via SIMD-0525, aims for further reductions toward a 200ms target.

Ethereum's better.codes contest tracks a 52.14-bit cryptographic proof gap for the koalaIRS12 parameter profile, measuring distance between certified safety and unsafe bounds via soundness and attack tracks.

Coldcard maker Coinkite released a security overhaul for Bitcoin hardware wallets following a firmware flaw that led to over $130 million in stolen Bitcoin.

Solana has upgraded its network for the first time since genesis, reducing base slot timing from 400ms to 350ms to speed up transaction confirmations. The change is part of a phased plan to reach 200ms, aiming to improve latency and censorship resistance.

A Bitcoin address tied to Maya Protocol's Aug. 18 exploit still held ~20.8 BTC worth $1.59M on Aug. 21, as technical analyses reveal broader pool damage exceeding initial estimates and recovery plans remain undefined.