Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    What Happens If the CLARITY Act Does Not Pass?
    What Happens If the CLARITY Act Does Not Pass?
    The Trump Crypto Presidency Power, Policy, and $1.4 Billion
    The Donald Trump Crypto Presidency: Power, Policy, and $2.3 Billion
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    The Robinhood Chain Paradox Built for Tokenized Stocks, Dominated by Memecoins
    The Robinhood Chain Paradox: Built for Tokenized Stocks, Dominated by Memecoins
  • Opinion
    OpinionShow More
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Bitcoin Treasury Blueprint What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    The Bitcoin Treasury Blueprint: What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Bitcoin News

Coldcard Hack Hits $75M After Alleged Second Attack Wave: Galaxy Research

The stolen funds remain unspent across seven attacker-controlled wallets as researchers continue monitoring their movements.

Written By Iyiola Adrian
Edited by Shubham Soni
Published 1 hour ago·Updated 1 hour ago
Make The Crypto Times preferred on GoogleGoogle
Coldcard Hack Hits $75M After Alleged Second Attack Wave: Galaxy Research

Key Highlights

  • Galaxy Research says the Coldcard hack has grown to $75.1 million, with 1,158.66 BTC stolen in two waves and the funds still sitting untouched.
  • Researchers linked both waves to the same Coldcard firmware flaw, warning that more attackers could target vulnerable wallets now that the weakness is public.
  • Chainalysis found the hacker targeted the biggest wallets first, helping steal over $38 million from about 500 wallets in just 25 minutes.

Galaxy Research, a blockchain research firm, has reported that the recent Coldcard wallet attack is much bigger than first believed, with the total amount of stolen Bitcoin now reaching 1,158.66 BTC, worth about $75.1 million. 

In a detailed X post on Saturday, the firm said more Bitcoin wallets were affected than originally reported, while the stolen funds remain untouched in wallets controlled by the attacker. 

We identified a 2nd wave of sweeps likely attributed to the same Coldcard hacker as the wave we described in the thread below.

We are now tracking 1,158.81 BTC stolen from 2,673 addresses and held unspent across 7 attacker addresses.

Updates to our analysis from yesterday 👇 https://t.co/UIDiRvw64K pic.twitter.com/2PHAWto9gx

— Galaxy Research (@glxyresearch) August 1, 2026

Stolen Bitcoin remains untouched 

Galaxy Research said it is tracking seven Bitcoin addresses holding the stolen funds. So far, none of the Bitcoin has been moved, which the company described as unusual for a theft of this size. 

According to the researchers, the attacker could be waiting for public attention to fade or may not yet have a safe way to move such a large amount of Bitcoin without attracting notice. 

“The proceeds have not moved. All 1,158.66 BTC remains unspent across the attacker addresses, which is unusual for a theft of this size and suggests the operator is either waiting out scrutiny or lacks a laundering path for a sum this visible,” Galaxy Research said. 

New findings point to the firmware flaw 

As the investigation continued, researchers found another key clue. They discovered that every Bitcoin stolen in both waves was created after March 17, 2021, the date when the vulnerable Coldcard firmware was released. The oldest stolen coins in both attacks were all linked to wallets created after that software became available. 

Galaxy Research said this is another strong sign that the thefts are connected to the same weakness in the wallet’s seed generation process. The firm added that it identified the attacker by studying transaction patterns on the blockchain, a method known as transaction fingerprinting. Much of that work was carried out by engineers at Block. 

Galaxy also warned that this may not be the only person trying to exploit the flaw. Now that details of the vulnerability are public, other attackers could begin targeting wallets created with the same weak firmware.

Because of that risk, the firm urged affected users to act quickly. It said anyone using a single-signature Coldcard-generated seed, particularly one created without sufficient additional randomness or a strong BIP-39 passphrase, should move their Bitcoin to a new wallet generated with a fresh recovery seed.

Chainalysis explains how the attack happened 

A day ago, blockchain analytics firm Chainalysis said the hacker did not steal Bitcoin randomly but carefully targeted the largest wallets first. 

According to the firm, the approach allowed the attacker to collect more than $30 million within the first 10 minutes of the attack. In about 25 minutes, nearly 594 BTC, worth more than $38 million at the time, had been taken from around 500 single-signature Bitcoin wallets. Chainalysis also found that one victim alone lost about $1.8 million. 

Coldcard bug opened the door for the theft 

The attack was later linked to a software flaw in certain Coldcard Mk3 hardware wallets made by Canadian company Coinkite. The company said some firmware versions released between March 2021 and version 5.0.3 did not generate recovery seeds with enough randomness. 

As a result, some seed phrases became significantly easier for attackers to guess using powerful computing resources.

Although Coinkite has released a software fix, it warned that simply updating the firmware is not enough. Users whose recovery seeds were created with the vulnerable software must generate an entirely new seed on updated hardware because old seeds remain at risk. 

Also Read: Bitcoin Price Watch: Lower $60,000s Range Holds Amid Security Concerns

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Binance Founder Warns Crypto Users After Coldcard Hack Tops $70M
Binance Founder Warns Crypto Users After Coldcard Hack Tops $70M 
Bank of Italy Study Questions Stablecoin Edge in Global Remittances 
Bank of Italy Study Questions Stablecoin Edge in Global Remittances 
SHIB Rallies 7% as Trading Volume Jumps 73% in 24 Hours
SHIB Rallies 7% as Trading Volume Jumps 73% in 24 Hours
XRP Ledger Rolls Out Update to Fix Manifest Flood Vulnerability
XRP Ledger Rolls Out Update to Fix Manifest Flood Vulnerability
Strategy’s Michael Saylor Backs CLARITY Act Ahead of Senate Recess
Strategy’s Michael Saylor Backs CLARITY Act Ahead of Senate Recess

Find Us on Socials

You may also like

Strategy Authorizes Up to $5B in Bitcoin Sales as 843,775 BTC Stack Sits $9B Underwater

Strategy Authorizes Up to $5B in Bitcoin Sales as 843,775 BTC Stack Sits $9B Underwater

Bitcoin Price Watch Lower $60,000s Support Holds Amid Security Concerns

Bitcoin Price Watch: Lower $60,000s Range Holds Amid Security Concerns

Coldcard Hacker Went After Largest Bitcoin Wallets First: Chainalysis

Coldcard Hacker Went After Largest Bitcoin Wallets First: Chainalysis

Bitcoin Price Slips Below $64,000 as $9.6B Options Expiry Settles

Bitcoin Price Slips Below $64,000 as $9.6B Options Expiry Settles

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information