• CONTACT
  • MARKETCAP
Coin  Deskk
  • BOOKMARKS
  • What’s New
  • Cryptocurrency
  • Pages
    • Contact Us
    • Search Page
    • Customize Interests
    • My Bookmarks
  • Home Coin
  • Home Coin
Reading: Galaxy estimates Coldcard exploit may have stolen up to 2,055 Bitcoin
Share
Coin  DeskkCoin  Deskk
Font ResizerAa
  • Home
  • Crypto
  • Market
  • Blockchain
  • Contact
Search
© 2026 Coindeskk News Network. All Rights Reserved.
What's New

Galaxy estimates Coldcard exploit may have stolen up to 2,055 Bitcoin

Crypto
Last updated: August 4, 2026 10:12 am
Crypto
Published: August 4, 2026
Share
Galaxy estimates Coldcard exploit may have stolen up to 2,055 Bitcoin

Galaxy Research has estimated that losses tied to the Coldcard hardware wallet vulnerability have reached 1,596 Bitcoin across confirmed attack waves and could climb to about 2,055 BTC, or nearly $130 million, if a suspected fourth wave is verified. Summary Galaxy Research estimates confirmed Coldcard related thefts have reached 1,596 Bitcoin across three attack waves. The research firm says losses could rise to about 2,055 Bitcoin worth nearly $130 million if a suspected fourth wave is confirmed. Investigators have shared confirmed attacker and victim addresses with U.S. law enforcement agencies, exchanges and cyber investigation groups. Around 90% of the stolen Bitcoin remains unmoved while affected Coldcard users are urged to generate new wallet seeds and migrate their funds. Galaxy Research said in a post published Monday on X that it has identified 1,596 BTC stolen from 7,300 addresses across three confirmed waves of attacks, along with 14 smaller security incidents linked to the Coldcard seed-generation flaw. 🚨LOSSES FROM COLDCARD HACK EXCEED $100M High confidence 1,596 BTC has been stolen from ~7300 addresses across 3 confirmed waves + more 14 smaller incidents. If we add suspected (but unconfirmed), the total balloons to $130m (2k BTC).More in the thread below 👇 pic.twitter.com/RAl3ib67qa— Galaxy Research (@glxyresearch) August 3, 2026 The research firm said its latest estimate excludes a fourth suspected attack wave because it has not yet received enough confirmation from affected wallet owners. If the additional activity is validated, the total would rise to 2,055 BTC, valued at about $130 million at current prices. Earlier blockchain analysis from Galaxy had estimated roughly 1,815.75 BTC moving across four observed waves, but the firm emphasized at the time that the figures came from on-chain analysis rather than confirmed victim reports. The latest update narrows confirmed losses while keeping the larger estimate tied to the still-unverified fourth wave. Coldcard attack investigation remains active Galaxy said it has identified what it believes is a fourth coordinated wave of theft but is still waiting for victim confirmation before adding those addresses to its confirmed tally. According to the research firm, blockchain activity suggests the suspected fourth wave is “substantially comprised of” one attacker, giving analysts medium-high confidence in that assessment despite the remaining uncertainty over affected wallets. Alex Thorn, Galaxy’s head of firmwide research, first flagged the potential fourth wave on Aug. 3 after identifying transaction patterns that closely matched the earlier attacks. His running estimate later rose to 448.7 BTC moving from 709 potential victim addresses, although Galaxy stressed that blockchain data alone cannot confirm every victim or determine whether a single operator carried out every theft. The firm added that its investigators continue refining address mapping as additional information becomes available from wallet owners and other participants in the investigation. Coldcard flaw dates back to 2021 firmware change The attacks stem from a vulnerability affecting seeds generated on Coldcard Mk3, Mk4, Mk5 and Coldcard Q devices running vulnerable firmware versions. Coinkite disclosed last week that the flaw originated in March 2021 while integrating a new cryptographic library into its firmware. Instead of generating wallet seeds through the intended hardware-backed true random number generator, affected firmware mistakenly relied on a deterministic pseudo-random generator provided by MicroPython. According to Coinkite’s technical review, the hardware random-number generator remained active elsewhere in the firmware, allowing internal reviews to confirm its presence without revealing that wallet creation had switched to a different entropy source. Block’s Bitcoin engineering and security team independently reached the same conclusion after reviewing the firmware. While the company said it had not completed full empirical testing of every affected device, it concluded that the vulnerable firmware called the deterministic MicroPython fallback instead of the STM32 hardware random-number generator during seed creation. Coinkite estimates that affected Mk2 and Mk3 devices may provide roughly 40 bits of effective entropy, while vulnerable Mk4, Mk5 and Coldcard Q models may generate about 72 bits instead of the intended 128 bits. Most stolen Bitcoin has not moved Galaxy said investigators have been working with U.S. federal law enforcement agencies, cryptocurrency exchanges and cyber investigation groups by sharing confirmed attacker and victim addresses as the investigation expands. The research firm reported that approximately 90% of the stolen Bitcoin remains untouched. It added that none of the coins stolen during the first three confirmed attack waves have moved since they were taken, giving investigators additional time to monitor the funds. Galaxy also warned that new attackers could attempt to exploit the same vulnerability while affected devices remain in use. For that reason, it said identifying additional attacker-controlled addresses remains important so exchanges and authorities can respond if funds begin moving. Earlier blockchain analysis showed attack activity accelerating to about 13.8 wallet sweeps per Bitcoin block during the fourth suspected wave, compared with roughly 0.3 sweeps per block before the incident. Galaxy also observed that most stolen balances were transferred to newly created addresses instead of one central collection wallet, while some funds later moved through second-hop transactions that complicated blockchain tracing. The firm previously noted that users who still control compromised wallets may have a limited opportunity to replace an unconfirmed theft transaction with a higher-fee transaction under Bitcoin’s Replace-by-Fee mechanism, although the option only exists before miners confirm the original transaction and offers no guarantee of recovery. Coldcard users are still urged to replace wallet seeds Galaxy said the attacks remain active and advised affected Coldcard users to move their funds to secure addresses and create entirely new wallet seeds on patched devices. Coinkite has already released emergency firmware updates for every affected product, including version 4.2.0 for Mk2 and Mk3 devices, version 5.6.0 for Mk4 and Mk5, version 1.5.0Q for Coldcard Q, and Edge releases 6.6.0X and 6.6.0QX. The company has also destroyed all remaining inventory containing vulnerable firmware. According to Coinkite, installing updated firmware protects only wallets created after the fix. Existing seed phrases generated with vulnerable firmware remain exposed and should be replaced. The company recommends generating a completely new seed after updating the device, verifying a receiving address, sending a small test transaction, and transferring the remaining balance only after confirming the test succeeds. Coinkite also said wallets created using at least 50 fair private dice rolls are not exposed by this random-number-generation issue alone. While a strong BIP-39 passphrase adds another security layer, the company continues to recommend migration because the original vulnerable seed remains weak.

Dogecoin’s $1 Dream Fades: Unseen Risks Loom, Investors Alert!
Polygon Surges Past Ethereum: POL Poised for Explosive Price Breakout?
Morgan Stanley’s MSBT avoids outflows through the first month of trading
Robinhood files $200M second venture fund focused on YC startups
Ripple targets AI agents with XRP as USDC dominates payments

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article South Korea’s Upbit lists HOME as Bithumb adds 2 tokens South Korea’s Upbit lists HOME as Bithumb adds 2 tokens
Next Article BitGo Link unifies exchange accounts for institutions BitGo Link unifies exchange accounts for institutions

Follow US

Find US on Socials
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
A16z Delves Deep: $70m Bet on EigenLayer Before EigenCloud Takes Off
Shiba Inu Plunges: Will It Survive This Critical Test?
Shiba Inu Plunges: Will It Survive This Critical Test?
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead
Solana Breaks Limits: Prepare for Unstoppable Blockchain Revolution Ahead

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin  Deskk

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

© Coindeskk News Network. All Rights Reserved.