Coldcard money map
Updated 19 August 2026. Still no new sweeps since 6 August, and the totals are unchanged: 1,778.84 BTC confirmed, about $112M, with 1,531 BTC of it never moved. New this week: investigators have found signs the targets may have been marked out months in advance, and the window for victims to act in the moment has closed.
A firmware bug let anyone who noticed guess the keys to thousands of “cold storage” Bitcoin wallets. Dozens of people did, over eight days in which 1,779 BTC, about $112.0M, was swept out. Then, on 6 August, it stopped. The typical coin taken had sat untouched for about three and a half years.
Follow the money
Pick a wave to follow it through. The width of every band is the amount of Bitcoin it carries, drawn to the same scale from one end to the other.
Then it stopped:
Stealing the coins took forty-one minutes. Spending them is the hard part: about 600 attacker addresses are now on a list held by US federal law enforcement, the exchanges and the compliance firms, and the big piles sit in plain sight, effectively frozen by the watching. Of the 246 BTC that has moved, Galaxy has two thirds going into CoinJoin and the rest travelling onward on-chain. Nothing was fixed on 6 August. Galaxy's reading of why it stopped is the bleak one: the vulnerable holders who were going to move their coins to safety had moved them, and the rest had already been emptied.
What the mixing looks like
Step figures unverifiedTRM Labs has the laundering, for now, down to two deposits: 64.9 BTC into Wasabi, a CoinJoin service, and 200 ETH into Tornado Cash, both on 4 August. Against $116M taken, that is a toe in the water. TRM reads the pattern as exploratory rather than the fast, practised laundering of a group like North Korea's TraderTraitor.
The steps below are one analyst's reading of how that Wasabi deposit moved, traced on 5 August. The deposit itself is confirmed; the round-by-round split is not, so the bars are hatched and every address and transaction is linked. Check the chain rather than take anyone's word for it.
-
1 64.9 BTC lands on one address
-
2 One transaction. Only about a sixth of it actually comes out mixed
change to bc1qajcr…svp2d3t
-
3 The 54 BTC goes back through, coming out in roughly 7 BTC pieces
those pieces are now being split again
The reported transaction chain, in the order given: e3274a1b, f3ee6e61, 3bdac8ed, 80f11c77. Which step each one belongs to has not been confirmed.
This is the shape a CoinJoin round leaves behind: a mixed portion comes out the far side, the remainder falls out as change, and the change goes round again. The point of it is to make one coin indistinguishable from the next, and pieces this large defeat that. A 7 BTC output has very little to hide among, so the coins stay recognisable on the way through. It reads less like laundering that works and more like someone finding out whether it can.
The numbers
| Wave | Date | BTC | USD | Wallets | How it was gathered |
|---|---|---|---|---|---|
| Wave 1 | Thu 30 Jul | 1,083 | $68.2M | 1,196 | Collector wallets, then one vault |
| Wave 2 | Sat 1 Aug | 76.01 | $4.8M | 1,477 | Collector wallets, then one vault |
| Wave 3 | Sun 2 Aug | 208 | $13.1M | 1,912 | Straight into hundreds of new addresses |
| 33+ smaller footprints | 30 Jul – 6 Aug | 412 | $25.9M | 4,015 | Straight into hundreds of new addresses |
| Unconfirmed episodessuspected | 3 – 6 Aug | 639 | $40.2M | 709 | Straight into hundreds of new addresses |
| Confirmed total | to 4 Aug | 1,779 | $112.0M | 8,600 | Both |
| With suspected wave 4 | to 4 Aug | 2,417 | $152.2M | 9,309 | Both |
Nobody touched a single device
A Bitcoin wallet is a very long random number. Coldcard devices are meant to draw that number from a dedicated hardware randomness chip. A build flag in a commit dated 1 March 2021 quietly rerouted it to MicroPython's built-in pseudo-random generator instead, which follows a pattern. It affects Mk3, Mk4, Mk5 and Q devices on firmware released after 17 March 2021. Reports name the release as both 4.0.0 and 4.0.1. The attacker ran the same shortcut on their own computer, generated the candidate wallets, and checked which ones held money.
- What it should be 128 bits
- Affected Mk4, Mk5, Q 72 bits
- Affected Mk2, Mk3 40 bits
There may also have been groundwork. Crystal Intelligence has found that a number of the addresses swept on 30 July had received dust, deposits worth a fraction of a penny, from a Wasabi wallet cluster in irregular bursts from December 2025 onward. One reading is that somebody was marking vulnerable addresses months before taking anything from them. Crystal is careful to call this a working theory: it has not ruled out coincidence or an unrelated dusting campaign, and is still counting how many victim addresses show the pattern.
Those bars understate it, because every bit doubles the work. 128 bits is more combinations than there are atoms in the visible universe. 40 bits is about a trillion, which is a weekend’s work for an ordinary computer.
Notes on the numbers
- Galaxy Research reported on 14 August that 1,778.84 BTC, about $112M, was taken from more than 8,600 addresses, and that it has seen no attacker activity since 6 August. Including episodes it has spotted but not confirmed, its estimate rises to 2,417.35 BTC, about $153M. Beside the three named waves it now counts at least 33 further attacker footprints.
- Waves 1–3 are the published running totals: 1,082.65 BTC from 1,196 addresses on 30 July, 1,158.66 BTC from 2,673 addresses by 1 August, and 1,367.05 BTC from 4,585 addresses by 2 August. The per-wave figures here are the differences between those totals. The “33+ smaller footprints” row is the remainder of Galaxy’s confirmed total, so the parts add up to 1,778.84 BTC and 8,600 addresses. That row is where the total keeps growing: 228.95 BTC on 4 August, 351.95 on 8 August, 411.79 now. The three named waves have not moved since 2 August.
- Galaxy publishes the moved-versus-unmoved split for the whole pile, not per wave. Galaxy's split is 1,531 BTC unmoved against 246 BTC moved, published for the confirmed total as a whole; the bands apply that same ratio to every row, including the unconfirmed ones, where it is an assumption rather than a figure. Galaxy says the coins that are moving are mostly the smaller opportunistic thefts, travelling through peel chains, cross-chain services and offshore casinos, while the large consolidated hoards sit untouched. On 4 August Galaxy put 1,158.66 BTC unspent across seven attacker-controlled addresses.
- Dollar figures use one reference rate of $62,963/BTC so the parts sum to the whole. As reported at the time, the numbers were $70.2M for wave 1 on 30 July, $75.1M cumulative on 1 August, $88.6M on 2 August and above $100M on 4 August.
- The “unconfirmed episodes” row is the gap between Galaxy's confirmed 1,778.84 BTC and its 2,417.35 BTC estimate including everything it has spotted. The sweep of 3 August, once called wave 4, is the largest known part of it at 448.7 BTC from 709 wallets. That 709 is the only address count published for any of it, so the all-in wallet total on this page is a floor rather than a sum.
- Galaxy's Alex Thorn notes the victim identification comes from blockchain analysis, not from device records, so the affected addresses are “likely Coldcard victims” rather than confirmed ones. Nobody outside Coinkite can see which device generated a given key. Galaxy has contacted 190 victims directly. It also says it cannot tell whether the waves and the 33 footprints belong to the same people or different ones, so the attacker count on this page is a count of distinct patterns, not of distinct humans.
- The mixing deposits are confirmed by TRM Labs: 64.9 BTC into Wasabi and 200 ETH into Tornado Cash, both on 4 August 2026, and nothing else so far. Chainalysis separately reports laundering through mixing services and cross-chain bridges, and Galaxy reports peel chains and offshore casinos for the smaller thefts. The round-by-round split of that Wasabi deposit is a single analyst's reading posted to X on 5 August, which no published source carries at that level of detail. The transactions could not be checked for this page, because every block explorer was unreachable from the machine that built it, so the cascade stays hatched with all addresses and transaction ids linked for anyone who wants to check them.
- Galaxy assesses with high confidence that at least some of the attackers used AI models stripped of their cybersecurity safeguards, naming the open-source Kimi K3 release as an example of the kind of system it means. That is an assessment about a class of tool, not a finding that any particular model was used here.
- The aftermath has moved into legal territory. Coinkite faces the threat of class action, with legal opinion split on whether it is liable, and on 6 August it disclosed that it has suspended the automatic deletion of customer data, which it normally purges after 120 days, to preserve records for “anticipated legal proceedings”. No lawsuit has been named as filed, three weeks on. That is an awkward reversal for a company whose pitch is privacy. Law firms on both sides of the Atlantic have begun publishing guidance for victims, and the consensus is that any claim against Coinkite would most likely be litigated in Canada.
- The sweeping has stopped but the story has not; last checked 19 August 2026. Galaxy's most recent published totals are from 4 August, and they have risen every day so far. Galaxy now counts at least fifteen separate attackers exploiting the same flaw, and TRM Labs independently traces the activity to at least fifteen distinct threat actors, some likely opportunistic copycats. So “the attacker” on this page means whoever ran a given wave, not one person behind all of them. TRM also notes the transaction construction differs between waves, which is the evidence for that.
Sources
- The Crypto Times: Coldcard hack losses hit $100M with 1,596 BTC stolen
- Fortune: What we know about the Coldcard exploit
- Bloomberg: Hackers target Bitcoin’s safest hiding place
- CoinDesk: An attack that never touched the devices
- The Hacker News: Coldcard flaw linked to $70M theft in 41 minutes
- Infosecurity Magazine: Coldcard users lose $89m
- Decrypt: Coldcard exploit balloons to $88 million
- Cryptopolitan: Coldcard wallets drained in four attack waves
- TechCrunch: Hackers steal over $130M by exploiting a bug in offline hardware wallets
- crypto.news: Fourth attack wave sweeps 448 BTC
- CoinDesk: The fourth sweep, and the replace-by-fee window it leaves open
- Coindoo: How some users can stop pending transfers
- TRM Labs: Inside the $116 million Coldcard hack
- GN Crypto: Attackers route 64 BTC and 200 ETH into mixers
- crypto.news: How a build flag drained $116M in Bitcoin
- The Crypto Times: Galaxy confirms $111M stolen, 1,719 BTC
- Crypto Briefing: Galaxy's analysis as losses climb past $111M
- Bitcoin.com: Coinkite faces a class action threat
- crypto.news: Coldcard halts customer data deletion over the exploit
- The Crypto Times: Galaxy says the attacks halted after 6 August
- Decrypt: Thefts slow, but losses could top $150 million
- The Crypto Times: Galaxy on attackers likely using unrestricted AI models
- ForkLog: Over 1,700 BTC stolen from vulnerable Coldcard wallets
- Crystal Intelligence: Tracing the Coldcard hack, and the dusting that preceded it
- Fieldfisher: What Coldcard victims need to know
- WeirFoulds: Why victims may have two routes to recovery
- Cointelegraph: At least 15 attackers exploited the Coldcard vulnerability
- The Crypto Times: Chainalysis on the attacker going after the largest wallets first
- Bitcoin World: Chainalysis on mixing services and cross-chain bridges
- Protos: 15 attackers now draining vulnerable Coldcard wallets
- CryptoSlate: The biggest Bitcoin movement since FTX, and where the smaller thefts are going
- CoinDesk: The hacker's wallet becomes a graffiti wall of pleas and hustles
Reusable with credit. The diagram prints cleanly on white, so use your browser’s print view for a press-ready copy.