Confirmed losses from the Coldcard hardware-wallet exploit have surpassed $100 million, blockchain research firm Galaxy Research said in an update on August 4. In a detailed thread, the firm said it has “high confidence” that 1,596 Bitcoin (BTC) has been stolen from roughly 7,300 addresses across three confirmed waves, plus 14 smaller incidents, a total worth more than $100 million at current prices.
If a suspected but still-unconfirmed fourth wave is included, Galaxy said, the figure could rise to around 2,055 BTC, or roughly $130 million. The firm was careful to keep the two categories separate, and it emphasized that the exploit remains active. The loss estimates have climbed steadily since the flaw came to light, from about $38 million when first discovered, to $88.6 million by the weekend, and continue to evolve as more victims come forward.
Confirmed vs. Suspected: What the Numbers Show
Galaxy drew a clear line between what it has verified and what it suspects. The confirmed total, 1,596 BTC across three waves and 14 smaller footprints, is based on victim reports and on-chain analysis, and the firm holds it with high confidence. The fourth wave, by contrast, has not been confirmed by any victim; Galaxy says it believes with “medium-high confidence” that the wave is substantially the work of an attacker, but has deliberately kept it out of its headline figure pending confirmation.
That distinction explains why loss estimates reported elsewhere have varied. As the fourth wave was detected earlier in the week, several outlets cited totals near $114–$116 million (about 1,816 BTC), a figure that combined an earlier confirmed count with the new wave. Galaxy’s August 4 update revised the confirmed portion upward to 1,596 BTC as additional victims came forward, which is why its confirmed-plus-suspected total now stands closer to $130 million. In a fast-moving, still-active incident, all of these figures should be read as running estimates rather than a final toll.
A Fourth Wave, Flagged Live
Unlike the first three waves, which were analyzed after the fact, the suspected fourth wave was called out while it was still happening. Galaxy’s Head of Research, Alex Thorn, warned on August 3 that a likely fourth organized wave was under way, initially identifying roughly 388.9 BTC moved across 218 transactions from 462 victim addresses into 216 newly created destinations, within a narrow band of blocks over about two and a half hours, a sweep rate the firm estimated at roughly 45 times the normal baseline. Later estimates put the wave nearer 448.7 BTC from about 709 addresses.
Thorn was transparent that this wave rested on on-chain pattern matching rather than direct victim reports, saying he had chosen to publish quickly to warn people while transactions were still pending. That timing mattered: some of the fourth-wave transactions used replace-by-fee (RBF), a Bitcoin feature that lets a sender replace an unconfirmed transaction with a higher-fee version. In practice, a victim who spots their coins sitting unconfirmed in the mempool may be able to pay a higher fee and move the funds to safety before the attacker’s transaction clears, a rare, time-sensitive chance to escape a sweep.
Possibly Multiple Attackers Now
Galaxy also signaled that the threat has broadened. While it believes each of the earlier mass waves was likely the work of a single operator, it said the 14 additional smaller footprints it has identified “could be many different attackers individually exploiting the now-known vulnerability.” On-chain patterns in the later activity, the firm and others noted, suggest multiple groups may now be racing to exploit the same firmware flaw, an expected consequence of the weakness becoming public knowledge. In total, Galaxy said 73 individual victims have come forward to help trace stolen coins.
Most Coins Haven’t Moved, and Are Being Traced
There is a more hopeful thread running through the update. Galaxy said roughly 90% of the stolen coins have not moved, and that 100% of the Bitcoin taken in the first three waves remains sitting in attacker-controlled addresses. Because those funds are visible and static on-chain, they remain traceable, and the firm said it has been supplying confirmed attacker and victim addresses, reportedly around 600 suspected attacker addresses, to U.S. federal law enforcement, crypto exchanges, and compliance and investigation firms. Galaxy also noted that none of the addresses hit in the first three waves were multisignature setups, consistent with the flaw affecting single-key seeds. The firm said there are still “hopes for recovery,” though it offered no guarantees.
The AI Question
The episode has also sharpened a debate about AI’s role in security. Thorn said the sweeps looked programmatic and were “probably orchestrated with a large language model.” Coldcard’s manufacturer, Coinkite, has said it must assume someone used AI to comb its open-source firmware for the flaw, and, notably, acknowledged that its own AI review of the same code weeks earlier had not found the bug. The uncomfortable implication both parties drew is that defenders and attackers had access to the same tools, and in this case the attacker found the weakness first. These are the assessments of the parties involved rather than a proven account of how the flaw was discovered.
What Coldcard Users Should Do
Galaxy’s guidance is unchanged and urgent: anyone using a Coldcard who is unsure whether their wallet is safe should migrate their funds to a safe destination, a custodian, an exchange, or a wallet built from a fresh seed. Critically, because the underlying seeds are already compromised, a firmware update alone does not fix an existing at-risk wallet. Coinkite has released emergency firmware for every affected model and said it destroyed its remaining inventory of devices carrying the vulnerable firmware; its TAPSIGNER, OPENDIME, and SATSCARD products are unaffected.
The scramble has been visible on-chain. According to CryptoQuant data cited in reporting, transfers of less than 1 BTC spiked toward levels last seen after the collapse of FTX, and the number of active Bitcoin addresses jumped toward one million in a day, signs of holders rushing to move funds. Bitcoin’s price, trading near $63,000, was little changed through the episode.
Background: The Firmware Flaw
The exploit traces to a March 2021 Coldcard firmware change that routed recovery-seed generation through a predictable software randomizer instead of the device’s hardware one, sharply reducing the entropy, the randomness, behind the seeds and leaving the resulting keys reproducible offline. That allowed attackers to precompute keys and sweep funds without ever touching a physical device. The Crypto Times has covered the unfolding attack, including the live fourth wave and the earlier escalation past $88 million.
The Bottom Line
More than a week after the first sweeps, the Coldcard exploit has become one of the largest self-custody thefts in Bitcoin’s history, and, unusually, one that is still in progress. Galaxy’s confirmed tally above $100 million is likely to keep shifting as victims report in and as opportunistic attackers probe the now-public flaw.
For holders, the takeaway is narrow and pressing: any single-signature Coldcard wallet created on the affected firmware should be treated as compromised and its funds moved without delay.
Also Read: $88M Coldcard Hack Reignites Bitcoin Custody War as Willy Woo Slams ETF Push
