The Coldcard money map
Snapshot: 4 August 2026. This is a live incident, and the totals have risen every day so far.
A firmware bug let someone guess the keys to thousands of “cold storage” Bitcoin wallets. As of 4 August 2026, roughly 1,596 BTC, about $100.1M, had been swept out in four waves over five days.
Follow the money
Pick a wave to follow it through. The width of every band is the amount of Bitcoin it carries, drawn to the same scale from one end to the other.
Where none of it has gone:
Stealing the coins took forty-one minutes. Spending them is the hard part: about 600 attacker addresses are now on a list held by US federal law enforcement, the exchanges and the compliance firms. The money is in plain sight and effectively frozen by the watching.
The numbers
| Wave | Date | BTC | USD | Wallets | How it was gathered |
|---|---|---|---|---|---|
| Wave 1 | Thu 30 Jul | 1,083 | $67.9M | 1,196 | Collector wallets, then one vault |
| Wave 2 | Sat 1 Aug | 76.01 | $4.8M | 1,477 | Collector wallets, then one vault |
| Wave 3 | Sun 2 Aug | 208 | $13.1M | 1,912 | Straight into hundreds of new addresses |
| 14 smaller sweeps | 30 Jul – 4 Aug | 229 | $14.4M | 2,715 | Straight into hundreds of new addresses |
| Wave 4suspected | Mon 3 Aug | 459 | $28.8M | 462 | Straight into hundreds of new addresses |
| Confirmed total | to 4 Aug | 1,596 | $100.1M | 7,300 | Both |
| With suspected wave 4 | to 4 Aug | 2,055 | $128.8M | 7,762 | Both |
Nobody touched a single device
A Bitcoin wallet is a very long random number. Coldcard devices are meant to draw that number from a dedicated hardware randomness chip. From a March 2021 firmware release, some of them quietly fell back to a software shortcut instead, one that follows a pattern. The attacker ran the same shortcut on their own computer, generated the candidate wallets, and checked which ones held money.
- What it should be 128 bits
- Affected Mk4, Mk5, Q 72 bits
- Affected Mk2, Mk3 40 bits
Those bars understate it, because every bit doubles the work. 128 bits is more combinations than there are atoms in the visible universe. 40 bits is about a trillion, which is a weekend’s work for an ordinary computer.
Notes on the numbers
- Galaxy Research reported on 4 August that it holds with high confidence that 1,596 BTC was taken from roughly 7,300 addresses across three confirmed waves plus fourteen smaller incidents. Including the suspected fourth wave takes it to about 2,055 BTC, or roughly $130M.
- Waves 1–3 are the published running totals: 1,082.65 BTC from 1,196 addresses on 30 July, 1,158.66 BTC from 2,673 addresses by 1 August, and 1,367.05 BTC from 4,585 addresses by 2 August. The per-wave figures here are the differences between those totals. The “14 smaller sweeps” row is the remainder of Galaxy’s confirmed total, so the parts add up to 1,596 BTC and 7,300 wallets.
- Galaxy publishes the moved-versus-unmoved split for the whole pile, not per wave. The bands split each wave in the same ≈90/10 proportion; the true per-wave split is not public. “Shuffled one hop further” means moved between the attacker’s own addresses. Galaxy also says 100% of the coins from the first three waves remains in attacker-controlled wallets.
- Dollar figures use one reference rate of $62,700/BTC so the parts sum to the whole. As reported at the time, the numbers were $70.2M for wave 1 on 30 July, $75.1M cumulative on 1 August, $88.6M on 2 August and above $100M on 4 August.
- This is a live incident. Figures are as of 4 August 2026 and the totals have risen every day so far.
Sources
- The Crypto Times: Coldcard hack losses hit $100M with 1,596 BTC stolen
- Fortune: What we know about the Coldcard exploit
- Bloomberg: Hackers target Bitcoin’s safest hiding place
- CoinDesk: An attack that never touched the devices
- The Hacker News: Coldcard flaw linked to $70M theft in 41 minutes
- Infosecurity Magazine: Coldcard users lose $89m
- Decrypt: Coldcard exploit balloons to $88 million
- Cryptopolitan: Coldcard wallets drained in four attack waves
Reusable with credit. The diagram prints cleanly on white, so use your browser’s print view for a press-ready copy.