The Coldcard money map

A firmware bug let anyone who noticed guess the keys to thousands of “cold storage” Bitcoin wallets. Dozens of people did. As of 8 August 2026, roughly 1,719 BTC, about $111.0M, had been swept out. The typical coin taken had sat untouched for about three and a half years.

1,719 BTC confirmed stolen ≈ $111.0M, as of 8 Aug 2026
7,300 wallets drained 25+ attack patterns
41 minutes to empty the first 1,196
≈90% has never moved since the big hoards sit untouched

Follow the money

Pick a wave to follow it through. The width of every band is the amount of Bitcoin it carries, drawn to the same scale from one end to the other.

Where the stolen Coldcard Bitcoin went A flow diagram in three stages: Bitcoin taken from victim wallets in four waves, gathered by the attackers into collector wallets or fresh addresses, and its status today, with roughly ninety per cent still sitting untouched. The same figures are available as a table below.
Band width = Bitcoin, to one scale throughout. Coloured bands are per-wave figures. The grey bands into stage 3 are deliberately not coloured by wave: the moved-versus-unmoved split is only published for the pile as a whole. Hatched = suspected, not yet confirmed. Data: Galaxy Research, to 8 August 2026 · Last checked 10 August 2026 · Chart: nader.io

The biggest hoard has not moved at all:

1,159 BTC sitting unspent across seven attacker addresses
0 BTC of it cashed out or run through a mixer

Stealing the coins took forty-one minutes. Spending them is the hard part: about 600 attacker addresses are now on a list held by US federal law enforcement, the exchanges and the compliance firms. The big piles sit in plain sight, effectively frozen by the watching. The smaller thefts are another matter, and those are already moving.

What the mixing looks like

Step figures unverified

TRM Labs has the laundering, for now, down to two deposits: 64.9 BTC into Wasabi, a CoinJoin service, and 200 ETH into Tornado Cash, both on 4 August. Against $116M taken, that is a toe in the water. TRM reads the pattern as exploratory rather than the fast, practised laundering of a group like North Korea's TraderTraitor.

The steps below are one analyst's reading of how that Wasabi deposit moved, traced on 5 August. The deposit itself is confirmed; the round-by-round split is not, so the bars are hatched and every address and transaction is linked. Check the chain rather than take anyone's word for it.

  1. 1 64.9 BTC lands on one address

    64.9 BTC

    bc1pynd6…zfqsdu7h92

  2. 2 One transaction. Only about a sixth of it actually comes out mixed

    54 BTC leaves as ordinary change ≈11

    change to bc1qajcr…svp2d3t

  3. 3 The 54 BTC goes back through, coming out in roughly 7 BTC pieces

    ≈7≈7≈7≈7≈7≈7≈7≈7

    those pieces are now being split again

The reported transaction chain, in the order given: e3274a1b, f3ee6e61, 3bdac8ed, 80f11c77. Which step each one belongs to has not been confirmed.

This is the shape a CoinJoin round leaves behind: a mixed portion comes out the far side, the remainder falls out as change, and the change goes round again. The point of it is to make one coin indistinguishable from the next, and pieces this large defeat that. A 7 BTC output has very little to hide among, so the coins stay recognisable on the way through. It reads less like laundering that works and more like someone finding out whether it can.

The numbers

Coldcard exploit, 30 July – 10 August 2026. Dollar figures at $64,572/BTC.
Wave Date BTC USD Wallets How it was gathered
Wave 1 Thu 30 Jul 1,083 $69.9M 1,196 Collector wallets, then one vault
Wave 2 Sat 1 Aug 76.01 $4.9M 1,477 Collector wallets, then one vault
Wave 3 Sun 2 Aug 208 $13.5M 1,912 Straight into hundreds of new addresses
Smaller incidents 30 Jul – 8 Aug 352 $22.7M 2,715 Straight into hundreds of new addresses
Wave 4suspected Mon 3 Aug 449 $29.0M 709 Straight into hundreds of new addresses
Confirmed total to 4 Aug 1,719 $111.0M 7,300 Both
With suspected wave 4 to 4 Aug 2,168 $140.0M 8,009 Both

Nobody touched a single device

A Bitcoin wallet is a very long random number. Coldcard devices are meant to draw that number from a dedicated hardware randomness chip. A build flag in a commit dated 1 March 2021 quietly rerouted it to MicroPython's built-in pseudo-random generator instead, which follows a pattern. It affects Mk3, Mk4, Mk5 and Q devices on firmware released after 17 March 2021. Reports name the release as both 4.0.0 and 4.0.1. The attacker ran the same shortcut on their own computer, generated the candidate wallets, and checked which ones held money.

  • What it should be 128 bits
  • Affected Mk4, Mk5, Q 72 bits
  • Affected Mk2, Mk3 40 bits

Those bars understate it, because every bit doubles the work. 128 bits is more combinations than there are atoms in the visible universe. 40 bits is about a trillion, which is a weekend’s work for an ordinary computer.

Notes on the numbers

  • Galaxy Research reported on 8 August that it holds with high confidence that 1,719 BTC, about $111M, was taken. It expects the eventual total to pass $130M as more cases are vetted, and now tracks more than 25 distinct attack patterns. The address count here, roughly 7,300, is Galaxy's 4 August figure and has not been restated alongside the higher coin total, so it probably lags.
  • Waves 1–3 are the published running totals: 1,082.65 BTC from 1,196 addresses on 30 July, 1,158.66 BTC from 2,673 addresses by 1 August, and 1,367.05 BTC from 4,585 addresses by 2 August. The per-wave figures here are the differences between those totals. The “Smaller incidents” row is the remainder of Galaxy’s confirmed total, so the parts add up to 1,719 BTC. That row is where the total has been growing: it began at 228.95 BTC on 4 August and is 351.95 BTC now.
  • Galaxy publishes the moved-versus-unmoved split for the whole pile, not per wave. The bands split each wave in the same ≈90/10 proportion; the true per-wave split is not public. Galaxy says the coins that are moving are mostly the smaller opportunistic thefts, travelling through peel chains, cross-chain services and offshore casinos, while the large consolidated hoards sit untouched. On 4 August Galaxy put 1,158.66 BTC unspent across seven attacker-controlled addresses.
  • Dollar figures use one reference rate of $64,572/BTC so the parts sum to the whole. As reported at the time, the numbers were $70.2M for wave 1 on 30 July, $75.1M cumulative on 1 August, $88.6M on 2 August and above $100M on 4 August.
  • Wave 4 uses Galaxy's own figure of 448.7 BTC from 709 wallets, which added to the published waves 1 to 3 exactly when it was counted: 1,815.75 BTC from 5,294 addresses. Treat the “with suspected wave 4” row as an upper bound rather than a sum. The confirmed total has been absorbing coins as they are vetted, so some of wave 4 may already be inside it, and adding the two would then count those coins twice.
  • Galaxy's Alex Thorn notes the victim identification comes from blockchain analysis, not from device records, so the affected addresses are “likely Coldcard victims” rather than confirmed ones. Nobody outside Coinkite can see which device generated a given key. Galaxy has now had reports from more than 250 individual victims, up from 73 in the first week.
  • The mixing deposits are confirmed by TRM Labs: 64.9 BTC into Wasabi and 200 ETH into Tornado Cash, both on 4 August 2026, and nothing else so far. Chainalysis separately reports laundering through mixing services and cross-chain bridges, and Galaxy reports peel chains and offshore casinos for the smaller thefts. The round-by-round split of that Wasabi deposit is a single analyst's reading posted to X on 5 August, which no published source carries at that level of detail. The transactions could not be checked for this page, because every block explorer was unreachable from the machine that built it, so the cascade stays hatched with all addresses and transaction ids linked for anyone who wants to check them.
  • The aftermath has moved into legal territory. Coinkite faces the threat of class action, with legal opinion split on whether it is liable, and on 6 August it disclosed that it has suspended the automatic deletion of customer data, which it normally purges after 120 days, to preserve records for “anticipated legal proceedings”. No lawsuit has been named as filed. That is an awkward reversal for a company whose pitch is privacy.
  • This is a live incident, last checked 10 August 2026. Galaxy's most recent published totals are from 4 August, and they have risen every day so far. Galaxy now counts at least fifteen separate attackers exploiting the same flaw, and TRM Labs independently traces the activity to at least fifteen distinct threat actors, some likely opportunistic copycats. So “the attacker” on this page means whoever ran a given wave, not one person behind all of them. TRM also notes the transaction construction differs between waves, which is the evidence for that.

Sources

Reusable with credit. The diagram prints cleanly on white, so use your browser’s print view for a press-ready copy.