Skip to main content

Coldcard Hardware Wallet Losses Approach $130 Million as Galaxy Flags Ongoing Multi-Attacker Exploit

Galaxy Research estimates up to 2,055 BTC stolen from Coldcard wallets due to a long-standing firmware entropy flaw, with at least 15 attackers and funds still at risk.

By CryptoPress
August 5, 2026

  • Galaxy Research has high confidence that 1,596 BTC (over $100 million) was stolen from roughly 7,300 addresses across three confirmed attack waves plus 14 smaller incidents.
  • Including a suspected fourth wave would raise the total to about 2,055 BTC, or roughly $130 million.
  • At least 15 separate attackers are now exploiting the vulnerability; 90% of stolen coins have not moved.
  • Coinkite has released emergency firmware updates and urged users to migrate funds to new seeds immediately.

Losses tied to a firmware vulnerability in Coinkite’s Coldcard bitcoin hardware wallets have climbed past $100 million and could reach approximately $130 million, according to on-chain analysis from Galaxy Research.

In a detailed thread posted Monday, Galaxy said it has high confidence that 1,596 BTC was drained from about 7,300 addresses across three confirmed waves of attacks plus 14 smaller incidents. Adding a still-unconfirmed fourth wave would bring the total to roughly 2,055 BTC.

The firm later noted that at least 15 different attackers appear to be exploiting the same flaw, with new footprints identified through victim reports. The Block reported that Galaxy is sharing confirmed attacker and victim addresses with U.S. federal law enforcement, exchanges, and cyber investigators.

The root cause is a firmware integration error dating to a 2021 migration. Instead of drawing entropy from the device’s hardware true random-number generator, affected versions fell back to a software pseudo-random number generator. On older Mk2 and Mk3 models the effective search space shrank to roughly 40 bits; later models that mixed in secure-element entropy still reached only about 72 bits against a 128-bit target, according to Coinkite’s technical backgrounder and detailed analysis by Decrypt.

Coinkite has released emergency firmware updates for all affected models (Mk3, Mk4, Mk5 and Coldcard Q), destroyed remaining vulnerable inventory, and repeatedly urged users to move funds. CEO Rodolfo Novak wrote that the company “will have to earn back our users’ trust,” while stressing that existing seeds generated on vulnerable firmware are not repaired by the update and must be replaced.

Galaxy emphasized the attack remains ongoing and that roughly 90% of the stolen bitcoin has not yet moved. Users whose seeds were generated without sufficient dice entropy or a strong BIP-39 passphrase are advised to generate a fresh seed on updated or alternative hardware and migrate funds promptly.

Related

© Cryptopress. All rights reserved.