The Coldcard hardware-wallet hack has entered a new and messier phase. Alex Thorn, Head of Research at Galaxy Research, said the firmware vulnerability is now being exploited by “numerous different attackers,” estimating there are “at least 15 different attackers” working through the remaining vulnerable wallets, a shift from the earlier picture of a few coordinated sweeps to what looks like an open scramble of independent actors and imitators.
The escalation comes as loss estimates continue to climb. On-chain analytics account Lookonchain, citing Galaxy Research, said the total losses from the Coldcard hack may have reached 2,055 BTC, roughly $130 million, affecting more than 7,700 victim addresses. That figure represents Galaxy’s suspected total, which includes an as-yet-unconfirmed fourth wave; the firm’s separately stated confirmed tally remains 1,596 BTC, or more than $100 million, across about 7,300 addresses.
From Coordinated Waves to a Swarm of Attackers
Galaxy had earlier attributed the theft largely to a small number of operators behind three main waves. That has changed. Now that the vulnerability is public and well understood, Thorn says a growing number of separate actors, including smaller imitators, are racing to exploit it, picking off the wallets that remain unmigrated. Galaxy said victim reports are helping it identify these new attacks and label the attackers, and that it continues to pass information to authorities.
The proliferation matters because it lengthens the danger window. Rather than a burst of activity from one attacker that ends, the exploit has become a persistent, distributed threat, with multiple parties independently checking the compromised key space and sweeping whatever value they find, down to very small balances. Analysts have warned this dynamic keeps pressure on any holder who has not yet moved funds off an affected device.
The Latest Numbers: Confirmed vs. Suspected
The distinction between what is confirmed and what is suspected remains important, and Galaxy has been careful to maintain it. Its high-confidence, victim-corroborated total sits at 1,596 BTC (over $100 million) across roughly 7,300 addresses in three waves plus 14 smaller footprints. Adding the suspected fourth wave, which Galaxy holds with “medium-high confidence” but has not confirmed through victim reports, lifts the figure to about 2,055 BTC, or $130 million, and the address count above 7,700, the number Lookonchain and other onchain analytics firms have highlighted.
These totals have risen steadily since the flaw surfaced, from an initial estimate around $38 million, and they should be read as evolving figures in an active investigation rather than a final accounting.
Long-Dormant Wallets, Long-Term Holders
One detail underscores who is being hit. Thorn noted that the stolen coins had, on average, sat untouched for about 3.18 years before being swept, meaning the victims were largely long-term holders who believed their Bitcoin was safely in cold storage. He has repeatedly warned that every single-signature Coldcard address created after the March 2021 firmware flaw will eventually be drained, describing it as only a matter of time, and urging users to move funds immediately.
An Inversion of “Not Your Keys, Not Your Coins”
The hack has produced an ironic reversal of one of Bitcoin’s core mantras. Faced with the risk that their self-custodied coins could be swept at any moment, many affected users have been moving Bitcoin back onto centralized exchanges such as Coinbase and Binance, or into freshly generated wallets, an unusual retreat from self-custody for a community that prizes it. At the same time, the incident has driven demand for on-chain tracing and asset-freezing services, as investigators work to flag attacker addresses before funds can be laundered.
There is still a measure of hope on the recovery side. As The Crypto Times reported, the large majority of the stolen coins have not moved and remain traceable on-chain, and Galaxy has been supplying attacker and victim addresses to U.S. federal law enforcement, exchanges and compliance firms.
What Coldcard Users Should Do
The guidance has not changed and remains urgent. The exploit stems from a March 2021 Coldcard firmware error that generated recovery seeds with too little randomness, leaving the resulting keys reproducible offline without any access to the physical device. Because those seeds are already compromised, updating firmware alone does not fix an existing at-risk wallet. Coinkite has released emergency firmware for all affected models and destroyed its remaining vulnerable inventory, but users who generated a single-signature seed on the affected firmware must move their funds to a wallet built from a completely new seed, or to a custodian or exchange.
The Bottom Line
What began as a single dramatic sweep has become a slow-burning, decentralized attack on one of Bitcoin’s most trusted cold-storage devices, now with at least 15 hands reaching for the same pool of vulnerable coins. With loss estimates still rising and new attackers emerging, the practical takeaway for anyone holding Bitcoin on an affected Coldcard is unchanged and time-sensitive: assume the old seed is compromised and move the funds without delay.
Also Read: Coldcard Hack Losses Hit $100M With 1,596 BTC Stolen in Ongoing Attack
