Loss estimates from the Coldcard hardware wallet exploit are continuing to rise as blockchain researchers link more addresses to a weakness introduced in Coinkite software updates in March 2021. The strongest published assessments currently place the theft between CryptoQuant’s 1,432 BTC confirmed tally and Galaxy Research’s 1,730 BTC high-confidence minimum, while TRM Labs estimates that roughly 1,816 BTC was taken across more than 5,200 addresses.
The gap between those figures reflects the limits of investigating a self-custody incident. Hardware wallet users do not appear in a centralized account database, so researchers must combine public victim reports with transaction tracing and known on-chain behavior. A victim who has not disclosed an affected address may remain outside the confirmed total even if their funds moved through wallets associated with the exploit.
Estimates depend on how researchers classify victims
CryptoQuant’s dashboard lists 1,432 BTC in confirmed losses. Moreno said the firm begins with public reports containing a wallet address or transaction ID, then compares those records against transaction patterns associated with the Coldcard exploit.
That methodology deliberately sets a high threshold. CryptoQuant does not classify wallets as victims solely because they resemble known exploit activity, Moreno said, since doing so could generate false positives and overstate the damage. Its number therefore represents a floor based on publicly identifiable cases rather than a complete count of every compromised wallet.
Galaxy Research has taken a broader tracing approach while retaining a distinction between high-confidence and suspected cases. Its latest assessment put the high-confidence minimum at 1,730 BTC as of Tuesday, after previously identifying a possible upper estimate of 1,816 BTC.
Thorn’s analysis identified more than 450 BTC tied to direct victim reports. Those disclosures then helped connect further addresses and unknown victims accounting for more than 730 BTC in total. Amounts judged potentially related but lacking sufficient corroboration have been kept outside the confirmed estimate, leaving room for the figure to change as victims come forward.
TRM Labs reached a similar upper-range estimate. Its recent review attributed approximately 1,816 BTC to the campaign, spread across more than 5,200 addresses and four waves of theft. Ari Redbord of TRM Labs said the total could continue increasing before it settles, as additional public disclosures make it possible to identify linked address clusters.
A software flaw exposed affected key generation
The incident centers on a weak random number generator included in Coldcard software updates released by Coinkite in March 2021. Randomness is a security requirement when a wallet creates the secret material behind private keys and recovery phrases. If the process produces values that are predictable enough, an attacker may be able to reconstruct keys without gaining access to a device, its PIN, or its physical backup.
According to the incident descriptions, the attackers exploited that weakness to guess private keys associated with affected wallet generation. The attack therefore differs from a conventional hardware-wallet theft involving a stolen device, phishing page, compromised computer, or disclosure of a recovery phrase.
A hardware wallet can remain physically secure while keys created under flawed software conditions are vulnerable. That distinction places the remediation burden on users whose recovery material was generated by affected releases: updating software alone would not change a seed phrase or private key that has already been created.
The four attack waves identified by TRM Labs suggest the stolen funds were not necessarily taken in a single, isolated event. Researchers can often recognize repeated campaigns through shared spending patterns, consolidation addresses, timing, and other blockchain behavior, though assigning each address requires different levels of confidence.
Public reporting shapes the confirmed total
The current figures should not be treated as interchangeable. CryptoQuant’s 1,432 BTC tally is based on cases that meet its confirmation criteria, while Galaxy Research and TRM Labs have included broader tracing results with separate confidence thresholds. The difference does not necessarily mean one group has found an entirely different set of victims; it can arise from where each researcher draws the line between verified theft, highly likely attribution, and uncorroborated suspicion.
No independent loss total has been published by Chainalysis for the incident. ZachXBT has also said publicly that he does not plan to track or trace the case, limiting the number of prominent public datasets that can be compared.
For affected Coldcard users, the practical concern is whether a wallet’s recovery phrase or private keys were generated using vulnerable software. A device upgrade would improve its current software state, but funds tied to previously generated weak key material would need to be moved to a newly created wallet using an updated environment and a fresh recovery phrase.
Users seeking to assess exposure should rely on Coinkite’s official incident guidance and identify the software version used when their wallet was initialized. They should avoid entering recovery phrases into websites or third-party tools while checking their status, since phishing attempts commonly follow major wallet-security incidents.
Worried about wallet exploits like this? Learn key crypto wallet security mistakes to avoid and harden your self-custody setup today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

