toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trading
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
Be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android app
More download options

Confirmed Coldcard wallet losses pass $100 million

2026-08-04 05:11

Confirmed losses linked to the Coldcard wallet incident have exceeded $100 million after attackers stole 1,596 Bitcoin from roughly 7,300 addresses, according to an Aug. 4 update from Galaxy Research. The total covers three major attack waves and 14 smaller incidents that investigators say were enabled by a flaw affecting the generation of wallet private keys.

Galaxy Research said it is also tracking a suspected fourth wave that could lift total losses to 2,055 BTC, worth about $130 million at the value used in its estimate. That cluster has not been added to the confirmed tally because affected holders have not yet directly reported the thefts.

The expanding estimate suggests the theft campaign reached far beyond the first identified victims. Galaxy’s team said 73 people had contacted its researchers, providing information that corroborated the three main waves and helped identify smaller transaction patterns, or “footprints,” potentially connected to the same vulnerability.

Galaxy said it has “medium-high” confidence that the suspected fourth wave was primarily attacker-driven activity. Direct victim confirmation remains absent for that group, leaving the higher estimate provisional.

Offline key guessing enabled the thefts

The incident stems from a weakness introduced in a March 2021 code update, according to the technical findings cited in the material. The flaw affected the device’s random-number generator, the component responsible for producing the unpredictable data used to create private keys.

Private keys control the Bitcoin held in a wallet. If a key is generated from sufficiently predictable values, an attacker can reproduce it through repeated guesses without obtaining the device, recovery phrase, PIN, or physical storage media.

Attackers appear to have exploited that weakness by using computing power to calculate affected private keys offline. The method meant stolen funds could be moved without direct contact with a victim’s hardware wallet, a fact that complicates the usual assumption that a device kept offline is inherently safe.

Security engineers at Block first identified the issue, according to the supplied account. Their analysis found that the vulnerable update caused affected devices to bypass their secure internal key-generation process, leaving the resulting keys far easier to predict than intended.

The first major attack was especially rapid. Galaxy’s findings indicate that 1,082 BTC were drained within 41 minutes in the initial wave, leaving little time for holders or wallet providers to react once the thefts began.

One reported victim, identified as Goodman, lost 18.25 BTC despite keeping an offline device in a bank safety deposit box. The case illustrates the particular risk created by a compromised setup process: physical isolation can protect a properly generated key from remote access, but cannot repair a key that was predictable from the day it was created.

Fourth wave remains under review

Galaxy’s prior report, released Saturday, had traced 1,367 BTC stolen across 4,585 addresses. The latest confirmed figure of 1,596 BTC adds 229 BTC and more than 2,700 addresses to the identified impact.

The large number of addresses should not automatically be read as an equivalent number of individual victims. A single holder can control multiple Bitcoin addresses, and attackers may also use several addresses to consolidate or route stolen coins. Yet the scale indicates that the exposure was distributed across a substantial set of wallet users rather than concentrated in a handful of large balances.

The research team said it continues to observe activity consistent with ongoing attacks. Its warning to potentially affected users was direct: holders uncertain about their exposure should move funds immediately to a safe address.

For vulnerable wallets, moving coins to another address within the same compromised recovery setup may not remove the risk. The recommended remedy is to transfer funds to wallets created with entirely new recovery phrases generated on patched systems. A new address is only useful if it is controlled by a newly generated, secure private key.

Using more than one hardware-wallet brand could also reduce the chance that a single undiscovered implementation flaw puts an entire Bitcoin balance at risk. That approach adds operational complexity, though it limits dependence on one device maker, firmware version, or key-generation process.

Most stolen Bitcoin has remained still

About 90% of the stolen Bitcoin has not moved, Galaxy said, including funds associated with the first three confirmed waves. Dormant stolen balances can make tracking easier on Bitcoin’s public ledger, although an unmoved balance does not establish who controls it or whether recovery will be possible.

Galaxy said it has shared attacker and victim addresses with U.S. federal law-enforcement agencies and cyber-investigation companies. The address data could help investigators monitor subsequent movements, identify exchanges or services receiving the funds, and connect activity across the separate attack waves.

The supplied data also points to an increase in daily Bitcoin transfers below one BTC, which reportedly reached 39,600, the highest level since November 2022. Small transfers can have many causes, but the timing is consistent with users splitting balances or moving funds away from potentially exposed wallets.

Galaxy’s research team also observed that the third confirmed wave used transaction patterns that differed from the first two. The change may indicate that another attacker adopted the same exploit or that the original operator changed techniques. Either scenario would make rapid migration more urgent for holders whose wallets may have been created under the affected 2021 code.

With losses now above 1,500 BTC and evidence of continued scanning for exposed wallets, the practical dividing line is whether a holder’s private keys were generated by an affected device and software version. For those who cannot rule that out, replacing the recovery phrase and moving funds to newly generated keys offers a more durable response than relying on an offline device or unchanged wallet address.


Worried about wallet security? Learn key protection steps in this crypto wallet safety guide and safeguard your Bitcoin.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trading
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.