Coldcard money map
Updated 3 September 2026. The hoards have started to move. After five weeks untouched, the wave 3 operator swapped about 20.5 BTC into Ether through THORChain, the first spend out of any of the three main piles. Galaxy now attributes 1,789.28 BTC, about $114.7M, across 8,865 addresses, of which 1,561 BTC has still never moved.
A firmware bug let anyone who noticed guess the keys to thousands of “cold storage” Bitcoin wallets. Dozens of people did, over eight days in which 1,789 BTC, about $114.7M, was swept out. Then, on 6 August, it stopped. Most of it has been sitting still ever since, in plain sight, while whoever took it works out how to spend it.
Follow the money
Pick a wave to follow it through. The width of every band is the amount of Bitcoin it carries, drawn to the same scale from one end to the other.
Then it stopped:
Stealing the coins took forty-one minutes. Spending them is the hard part: about 600 attacker addresses are now on a list held by US federal law enforcement, the exchanges and the compliance firms, and the big piles sit in plain sight, effectively frozen by the watching. Nothing was fixed on 6 August. Galaxy's reading of why the sweeping stopped is the bleak one: the vulnerable holders who were going to move their coins to safety had moved them, and the rest had already been emptied. What changed on 3 September is the other end of the pipe. One of the three main piles moved for the first time, which is the test of whether being watched actually stops anyone.
Getting it out
Step figures unverifiedThree attempts so far, all small against $114.7M taken. On 4 August, TRM Labs traced 64.9 BTC into Wasabi, a CoinJoin service, and 200 ETH into Tornado Cash. Then nothing for five weeks. On 3 September the wave 3 operator moved about 20.5 BTC, roughly a tenth of that wave, out of a two-of-two multisig vault through a chain of hops and into THORChain, swapping it for Ether. It is the first spend out of any of the three main hoards.
It did not go smoothly. THORChain refunded several of the swap attempts and the operator resubmitted them; Galaxy has not established why, and points at liquidity, transaction settings or the protocol's own safeguards as possibilities. The Ether landed on a freshly made address, which has been passed to law enforcement, the exchanges and the compliance firms, so the coins have swapped chains without shaking anyone off. TRM still reads the whole pattern as exploratory rather than the practised laundering of a group like North Korea's TraderTraitor.
The steps below are one analyst's reading of how the Wasabi deposit moved, traced on 5 August. The deposit itself is confirmed; the round-by-round split is not, so the bars are hatched and every address and transaction is linked. Check the chain rather than take anyone's word for it.
-
1 64.9 BTC lands on one address
-
2 One transaction. Only about a sixth of it actually comes out mixed
change to bc1qajcr…svp2d3t
-
3 The 54 BTC goes back through, coming out in roughly 7 BTC pieces
those pieces are now being split again
The reported transaction chain, in the order given: e3274a1b, f3ee6e61, 3bdac8ed, 80f11c77. Which step each one belongs to has not been confirmed.
This is the shape a CoinJoin round leaves behind: a mixed portion comes out the far side, the remainder falls out as change, and the change goes round again. The point of it is to make one coin indistinguishable from the next, and pieces this large defeat that. A 7 BTC output has very little to hide among, so the coins stay recognisable on the way through. It reads less like laundering that works and more like someone finding out whether it can.
The numbers
| Wave | Date | BTC | USD | Wallets | How it was gathered |
|---|---|---|---|---|---|
| Wave 1 | Thu 30 Jul | 1,083 | $69.4M | 1,196 | Collector wallets, then one vault |
| Wave 2 | Sat 1 Aug | 76.01 | $4.9M | 1,477 | Collector wallets, then one vault |
| Wave 3 | Sun 2 Aug | 208 | $13.4M | 1,912 | Straight into hundreds of new addresses |
| 33+ smaller footprints | 30 Jul – 6 Aug | 422 | $27.1M | 4,280 | Straight into hundreds of new addresses |
| Unconfirmed episodessuspected | 3 – 6 Aug | 639 | $40.9M | 709 | Straight into hundreds of new addresses |
| Confirmed total | to 4 Aug | 1,789 | $114.7M | 8,865 | Both |
| With suspected wave 4 | to 4 Aug | 2,428 | $155.6M | 9,574 | Both |
Nobody touched a single device
A Bitcoin wallet is a very long random number. Coldcard devices are meant to draw that number from a dedicated hardware randomness chip. A build flag in a commit dated 1 March 2021 quietly rerouted it to MicroPython's built-in pseudo-random generator instead, which follows a pattern. It affects Mk3, Mk4, Mk5 and Q devices on firmware released after 17 March 2021. Reports name the release as both 4.0.0 and 4.0.1. The attacker ran the same shortcut on their own computer, generated the candidate wallets, and checked which ones held money.
- What it should be 128 bits
- Affected Mk4, Mk5, Q 72 bits
- Affected Mk2, Mk3 40 bits
There may also have been groundwork. Crystal Intelligence has found that a number of the addresses swept on 30 July had received dust, deposits worth a fraction of a penny, from a Wasabi wallet cluster in irregular bursts from December 2025 onward. One reading is that somebody was marking vulnerable addresses months before taking anything from them. Crystal is careful to call this a working theory: it has not ruled out coincidence or an unrelated dusting campaign, and is still counting how many victim addresses show the pattern.
Those bars understate it, because every bit doubles the work. 128 bits is more combinations than there are atoms in the visible universe. 40 bits is about a trillion, which is a weekend’s work for an ordinary computer.
Notes on the numbers
- Galaxy Research reported on 14 August that 1,778.84 BTC, about $112M, was taken from more than 8,600 addresses, and that it has seen no attacker activity since 6 August. Including episodes it has spotted but not confirmed, its estimate rises to 2,417.35 BTC, about $153M. Beside the three named waves it now counts at least 33 further attacker footprints.
- Waves 1–3 are the published running totals: 1,082.65 BTC from 1,196 addresses on 30 July, 1,158.66 BTC from 2,673 addresses by 1 August, and 1,367.05 BTC from 4,585 addresses by 2 August. The per-wave figures here are the differences between those totals. The “33+ smaller footprints” row is the remainder of Galaxy’s confirmed total, so the parts add up to 1,778.84 BTC and 8,600 addresses. That row is where the total keeps growing: 228.95 BTC on 4 August, 351.95 on 8 August, 411.79 now. The three named waves have not moved since 2 August.
- Galaxy publishes the moved-versus-unmoved split for the whole pile, not per wave. Galaxy's split is 1,531 BTC unmoved against 246 BTC moved, published for the confirmed total as a whole; the bands apply that same ratio to every row, including the unconfirmed ones, where it is an assumption rather than a figure. Galaxy says the coins that are moving are mostly the smaller opportunistic thefts, travelling through peel chains, cross-chain services and offshore casinos, while the large consolidated hoards sit untouched. On 4 August Galaxy put 1,158.66 BTC unspent across seven attacker-controlled addresses.
- Dollar figures use one reference rate of $64,104/BTC so the parts sum to the whole. As reported at the time, the numbers were $70.2M for wave 1 on 30 July, $75.1M cumulative on 1 August, $88.6M on 2 August and above $100M on 4 August.
- The “unconfirmed episodes” row is the gap between Galaxy's confirmed 1,778.84 BTC and its 2,417.35 BTC estimate including everything it has spotted. The sweep of 3 August, once called wave 4, is the largest known part of it at 448.7 BTC from 709 wallets. That 709 is the only address count published for any of it, so the all-in wallet total on this page is a floor rather than a sum.
- Galaxy's Alex Thorn notes the victim identification comes from blockchain analysis, not from device records, so the affected addresses are “likely Coldcard victims” rather than confirmed ones. Nobody outside Coinkite can see which device generated a given key. Galaxy has had 221 reports covering 790.72 BTC, about 44% of the total it attributes to the exploit; the median reported loss is 1.04 BTC and the average 3.58, which is the gap between the many people who lost a little and the few who lost a lot. It also says it cannot tell whether the waves and the 33 footprints belong to the same people or different ones, so the attacker count on this page is a count of distinct patterns, not of distinct humans.
- The mixing deposits are confirmed by TRM Labs: 64.9 BTC into Wasabi and 200 ETH into Tornado Cash, both on 4 August 2026, and nothing else so far. Chainalysis separately reports laundering through mixing services and cross-chain bridges, and Galaxy reports peel chains and offshore casinos for the smaller thefts. The round-by-round split of that Wasabi deposit is a single analyst's reading posted to X on 5 August, which no published source carries at that level of detail. The transactions could not be checked for this page, because every block explorer was unreachable from the machine that built it, so the cascade stays hatched with all addresses and transaction ids linked for anyone who wants to check them.
- Galaxy assesses with high confidence that at least some of the attackers used AI models stripped of their cybersecurity safeguards, naming the open-source Kimi K3 release as an example of the kind of system it means. That is an assessment about a class of tool, not a finding that any particular model was used here.
- The aftermath has moved into legal territory. Coinkite faces the threat of class action, with legal opinion split on whether it is liable, and on 6 August it disclosed that it has suspended the automatic deletion of customer data, which it normally purges after 120 days, to preserve records for “anticipated legal proceedings”. No lawsuit has been named as filed, three weeks on. That is an awkward reversal for a company whose pitch is privacy. Law firms on both sides of the Atlantic have begun publishing guidance for victims, and the consensus is that any claim against Coinkite would most likely be litigated in Canada.
- The sweeping has stopped but the story has not; last checked 3 September 2026. Galaxy's most recent published totals are from 4 August, and they have risen every day so far. Galaxy now counts at least fifteen separate attackers exploiting the same flaw, and TRM Labs independently traces the activity to at least fifteen distinct threat actors, some likely opportunistic copycats. So “the attacker” on this page means whoever ran a given wave, not one person behind all of them. TRM also notes the transaction construction differs between waves, which is the evidence for that.
Sources
- The Crypto Times: Coldcard hack losses hit $100M with 1,596 BTC stolen
- Fortune: What we know about the Coldcard exploit
- Bloomberg: Hackers target Bitcoin’s safest hiding place
- CoinDesk: An attack that never touched the devices
- The Hacker News: Coldcard flaw linked to $70M theft in 41 minutes
- Infosecurity Magazine: Coldcard users lose $89m
- Decrypt: Coldcard exploit balloons to $88 million
- Cryptopolitan: Coldcard wallets drained in four attack waves
- TechCrunch: Hackers steal over $130M by exploiting a bug in offline hardware wallets
- crypto.news: Fourth attack wave sweeps 448 BTC
- CoinDesk: The fourth sweep, and the replace-by-fee window it leaves open
- Coindoo: How some users can stop pending transfers
- TRM Labs: Inside the $116 million Coldcard hack
- GN Crypto: Attackers route 64 BTC and 200 ETH into mixers
- crypto.news: How a build flag drained $116M in Bitcoin
- The Crypto Times: Galaxy confirms $111M stolen, 1,719 BTC
- Crypto Briefing: Galaxy's analysis as losses climb past $111M
- Bitcoin.com: Coinkite faces a class action threat
- crypto.news: Coldcard halts customer data deletion over the exploit
- The Crypto Times: Galaxy says the attacks halted after 6 August
- Decrypt: Thefts slow, but losses could top $150 million
- The Crypto Times: Galaxy on attackers likely using unrestricted AI models
- ForkLog: Over 1,700 BTC stolen from vulnerable Coldcard wallets
- Crystal Intelligence: Tracing the Coldcard hack, and the dusting that preceded it
- Fieldfisher: What Coldcard victims need to know
- WeirFoulds: Why victims may have two routes to recovery
- Cointelegraph: Galaxy finds 1,561 BTC still unmoved
- Cointelegraph: The wave 3 hacker swaps stolen Bitcoin through THORChain
- crypto.news: Refunds and retries on the THORChain swaps
- The Crypto Times: $115M lost across 8,865 addresses
- Cointelegraph: At least 15 attackers exploited the Coldcard vulnerability
- The Crypto Times: Chainalysis on the attacker going after the largest wallets first
- Bitcoin World: Chainalysis on mixing services and cross-chain bridges
- Protos: 15 attackers now draining vulnerable Coldcard wallets
- CryptoSlate: The biggest Bitcoin movement since FTX, and where the smaller thefts are going
- CoinDesk: The hacker's wallet becomes a graffiti wall of pleas and hustles
Reusable with credit. The diagram prints cleanly on white, so use your browser’s print view for a press-ready copy.