Confirmed losses linked to the Coldcard wallet incident have exceeded $100 million after attackers stole 1,596 Bitcoin from roughly 7,300 addresses, according to an Aug. 4 update from Galaxy Research. The total covers three major attack waves and 14 smaller incidents that investigators say were enabled by a flaw affecting the generation of wallet private keys.
Galaxy Research said it is also tracking a suspected fourth wave that could lift total losses to 2,055 BTC, worth about $130 million at the value used in its estimate. That cluster has not been added to the confirmed tally because affected holders have not yet directly reported the thefts.
The expanding estimate suggests the theft campaign reached far beyond the first identified victims. Galaxy’s team said 73 people had contacted its researchers, providing information that corroborated the three main waves and helped identify smaller transaction patterns, or “footprints,” potentially connected to the same vulnerability.
Galaxy said it has “medium-high” confidence that the suspected fourth wave was primarily attacker-driven activity. Direct victim confirmation remains absent for that group, leaving the higher estimate provisional.
Offline key guessing enabled the thefts
The incident stems from a weakness introduced in a March 2021 code update, according to the technical findings cited in the material. The flaw affected the device’s random-number generator, the component responsible for producing the unpredictable data used to create private keys.
Private keys control the Bitcoin held in a wallet. If a key is generated from sufficiently predictable values, an attacker can reproduce it through repeated guesses without obtaining the device, recovery phrase, PIN, or physical storage media.
Attackers appear to have exploited that weakness by using computing power to calculate affected private keys offline. The method meant stolen funds could be moved without direct contact with a victim’s hardware wallet, a fact that complicates the usual assumption that a device kept offline is inherently safe.
Security engineers at Block first identified the issue, according to the supplied account. Their analysis found that the vulnerable update caused affected devices to bypass their secure internal key-generation process, leaving the resulting keys far easier to predict than intended.
The first major attack was especially rapid. Galaxy’s findings indicate that 1,082 BTC were drained within 41 minutes in the initial wave, leaving little time for holders or wallet providers to react once the thefts began.
One reported victim, identified as Goodman, lost 18.25 BTC despite keeping an offline device in a bank safety deposit box. The case illustrates the particular risk created by a compromised setup process: physical isolation can protect a properly generated key from remote access, but cannot repair a key that was predictable from the day it was created.
Fourth wave remains under review
Galaxy’s prior report, released Saturday, had traced 1,367 BTC stolen across 4,585 addresses. The latest confirmed figure of 1,596 BTC adds 229 BTC and more than 2,700 addresses to the identified impact.
The large number of addresses should not automatically be read as an equivalent number of individual victims. A single holder can control multiple Bitcoin addresses, and attackers may also use several addresses to consolidate or route stolen coins. Yet the scale indicates that the exposure was distributed across a substantial set of wallet users rather than concentrated in a handful of large balances.
The research team said it continues to observe activity consistent with ongoing attacks. Its warning to potentially affected users was direct: holders uncertain about their exposure should move funds immediately to a safe address.
For vulnerable wallets, moving coins to another address within the same compromised recovery setup may not remove the risk. The recommended remedy is to transfer funds to wallets created with entirely new recovery phrases generated on patched systems. A new address is only useful if it is controlled by a newly generated, secure private key.
Using more than one hardware-wallet brand could also reduce the chance that a single undiscovered implementation flaw puts an entire Bitcoin balance at risk. That approach adds operational complexity, though it limits dependence on one device maker, firmware version, or key-generation process.
Most stolen Bitcoin has remained still
About 90% of the stolen Bitcoin has not moved, Galaxy said, including funds associated with the first three confirmed waves. Dormant stolen balances can make tracking easier on Bitcoin’s public ledger, although an unmoved balance does not establish who controls it or whether recovery will be possible.
Galaxy said it has shared attacker and victim addresses with U.S. federal law-enforcement agencies and cyber-investigation companies. The address data could help investigators monitor subsequent movements, identify exchanges or services receiving the funds, and connect activity across the separate attack waves.
The supplied data also points to an increase in daily Bitcoin transfers below one BTC, which reportedly reached 39,600, the highest level since November 2022. Small transfers can have many causes, but the timing is consistent with users splitting balances or moving funds away from potentially exposed wallets.
Galaxy’s research team also observed that the third confirmed wave used transaction patterns that differed from the first two. The change may indicate that another attacker adopted the same exploit or that the original operator changed techniques. Either scenario would make rapid migration more urgent for holders whose wallets may have been created under the affected 2021 code.
With losses now above 1,500 BTC and evidence of continued scanning for exposed wallets, the practical dividing line is whether a holder’s private keys were generated by an affected device and software version. For those who cannot rule that out, replacing the recovery phrase and moving funds to newly generated keys offers a more durable response than relying on an offline device or unchanged wallet address.
Worried about wallet security? Learn key protection steps in this crypto wallet safety guide and safeguard your Bitcoin.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

