Coldcard Bitcoin Theft Toll Clears $112 Million — And the Quiet Since August 6 Is Not the Reassurance It Seems
• August 16, 2026 7:18 am • CommentsA hardware wallet is supposed to put distance between your Bitcoin and an attacker. For a growing group of Coldcard owners, the device itself appears to have supplied the opening.
Galaxy Research says it now has very high confidence that more than 1,778 BTC was stolen through a Coldcard seed-recreation exploit. That was worth roughly $112 million at the firm’s measured price, and Galaxy expects the final total to climb.
The attacks have slowed. That is the good news.
The dangerous part is why they may have slowed.
COLDCARD ATTACKS EASE, BUT LOSSES CLIMB
We have very high confidence that total BTC stolen in the Coldcard exploit has exceeded 1,778 BTC ($112m), though final number will be higher.
That doesn't mean attacks cannot continue — if you are still storing keys on Coldcard device,… pic.twitter.com/LURQuv0v3K
— Galaxy Research (@glxyresearch) August 14, 2026
The lull does not close the vulnerability.
Decrypt’s review of Galaxy’s findings says no confirmed attacker activity appeared after August 6. Galaxy’s working explanation is not that the underlying method suddenly stopped working, and new victims were still contacting researchers as the firm attributed additional losses.
Many exposed owners may have moved their coins—or attackers may already have emptied the easiest targets. Galaxy had spoken directly with more than 190 victims, giving the firm owner-level evidence to pair with the address patterns visible on-chain.
That distinction matters. A quiet address is not the same thing as a fixed device.
The suspected weakness traces back to a 2021 firmware change affecting seed generation. According to the reporting, the change moved part of that process away from the hardware random-number chip and into a software substitute.
The resulting seeds could have far less effective randomness than users believed.
Attackers did not need to trick a holder into handing over a recovery phrase. They could attempt to reconstruct vulnerable seeds from information tied to a device, including its serial number and clock state, and then sweep the funds on-chain.
The reporting dates the known attack activity to at least July 30. That timeline helps explain why Galaxy treats the August 6 cutoff as a change in observed activity, not proof that every exposed seed is now safe.
The chain data shows how concentrated the damage became.
Galaxy’s breakdown identifies three major theft waves and more than 30 smaller footprints. The largest confirmed wave removed 1,082.65 BTC from 1,195 addresses in its opening minutes.
Another owner-confirmed cluster took 209.94 BTC across 2,148 addresses, while a third major wave accounted for another 208.24 BTC.
Altogether, the firm has mapped more than 5,200 drained addresses and spoken directly with more than 190 victims. Most of the confirmed stolen Bitcoin remained in attacker-controlled addresses when Galaxy took its snapshot.
Investigators can watch those coins. The owners still cannot spend them.
A suspected fourth wave could push the total to 2,417 BTC. At the prices used in the reporting, that would put losses above $150 million.
Coldcard Bitcoin Thefts Slow, But Losses Could Top $150 Million: Galaxyhttps://t.co/eAJ5lzqHSR
— Decrypt (@DecryptMedia) August 14, 2026
What Coldcard holders should take from this.
The practical warning is narrower than a blanket indictment of self-custody. The reported exposure centers on seeds generated by affected Coldcard firmware and held in single-signature wallets.
A holder who moved funds to a fresh seed generated through a sound process is in a different position from one who simply stopped using an old device while leaving the same coins at the same vulnerable addresses.
Galaxy continues to urge potentially affected single-signature users to move funds to fresh addresses. Owners should avoid unsolicited recovery help, direct messages, or links that ask for seed words.
The bigger lesson is uncomfortable but useful: hardware can reduce entire classes of risk, yet the security of the wallet still depends on how its secret is created. If that foundation is weak, the reassuring plastic case around it cannot save the coins.
Join the conversation!
We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.
