Key Highlights
- Galaxy Research identified a third attack wave, raising the Coldcard exploit to 1,367 BTC ($88.6M).
- Researchers found distinct attack patterns, suggesting either an evolved attacker or a separate threat actor.
- All stolen BTC remains unspent, prompting renewed warnings for Coldcard users to migrate funds to secure wallets.
Galaxy Research, the blockchain research firm, has revised its estimate of the Coldcard wallet exploit, revealing a third wave of attacks that has pushed the total stolen Bitcoin (BTC) to 1,367.05 BTC, worth approximately $88.6 million, across 4,585 addresses.
In a detailed X post on August 1, 2026, the firm reported a new attack wave in which 207.7294 BTC was drained. According to Galaxy, the cumulative total from all three attack waves now stands at 1,366.3865 BTC held unspent across attacker-controlled addresses.
Galaxy identifies distinct attack patterns
Galaxy Research said Waves 1 and 2 shared several characteristics, including common collector addresses, identical P2WPKH destination addresses, and similar derivation paths. The attacks occurred about 27 hours apart, suggesting they were likely carried out by the same operator.
However, Wave 3 differed significantly. According to Galaxy, it used individual destination addresses for each victim, relied on P2WSH outputs, grouped multiple victims into single batches, and targeted only the default derivation path.
Galaxy said these differences could indicate either that the original attacker adopted new techniques to avoid detection or that a separate threat actor exploited the same vulnerability. Researchers also noted that all attacker-controlled addresses remain unspent, describing that as unusual for a theft of this scale.
The report found that while most affected wallets held less than 1 BTC, the majority of the stolen value came from larger wallets, consistent with individual self-custody users rather than institutional holders. Galaxy also said all compromised addresses were created after the vulnerable Coldcard firmware was released in March 2021.
This follows Galaxy Research’s previous report, which estimated the theft at 1,158.66 BTC, amounting to $75.1 million. At the time, the firm highlighted that none of the funds had moved, suggesting the attacker was either waiting for attention to subside or lacked a safe laundering path for such a visible sum.
Concerns about hardware wallet security
The latest findings have renewed concerns within the Bitcoin self-custody community about the security of hardware wallets and the risks associated with seed phrase generation. Coldcard users have been urged to take immediate precautions, including migrating funds to new, secure setups.
The incident has also renewed attention on the risks associated with firmware vulnerabilities in hardware wallets. With the stolen funds still unmoved, researchers continue to monitor the attacker-controlled addresses while urging potentially affected users to replace vulnerable recovery seeds and migrate funds to new wallets.
Also Read: Michael Saylor Says BIP-110 Lacks Bitcoin Economic Consensus
