The Coldcard firmware exploit that began on July 30 now has a confirmed number attached to it. Galaxy Research, working with 73 individual victims on tracing, puts the total at 1,596 BTC drained across more than 7,300 addresses. At the $63,500 to $64,000 range Bitcoin has traded this week, that is north of $100 million, making it one of the largest single-vector self-custody losses on record.
The root cause is not a new bug. It is a weak random-number generator in a firmware build dating to March 2021, which degraded the entropy used during seed generation. Any wallet initialised on an affected build produced a seed drawn from a search space small enough to be reconstructed offline. No phishing, no malicious signing prompt, no compromised host machine. The keys were guessable from the moment they were created, and they stayed guessable for five years.
The Timeline
The attack arrived in distinct waves rather than as one sweep:
- July 30: first wave, roughly 594 BTC from close to 500 addresses inside a 25-minute window
- August 1 and 2: second and third waves, spreading to approximately 4,500 addresses as losses passed $89 million
- August 4: Galaxy confirms 1,596 BTC across three waves plus 14 smaller footprints, more than 7,300 addresses total
The tight clustering of the first wave is the tell. Sweeping 500 addresses in 25 minutes means the attacker had the full key list precomputed and was simply broadcasting. The later waves were not new discoveries so much as the same list worked through in stages, likely to manage mempool congestion and fee spikes.
Coinkite's Response
Coinkite, the manufacturer, has released patched firmware alongside migration instructions, halted shipments, and destroyed remaining inventory built on the vulnerable build. Users of affected devices are being told to generate an entirely new seed rather than merely update, because the update fixes future entropy and does nothing about a key that was already weak.
That distinction is the single most important operational detail in this story and it is the one most likely to be missed. Updating firmware does not rotate an existing seed. If your device was initialised on an affected build, the only remediation is a fresh seed on patched firmware and a full sweep of funds to new addresses.
The Coins Are Still Sitting There
Roughly 90% of the stolen BTC remains static and traceable, per Galaxy's tracking. That is unusual and worth thinking about carefully.
An attacker who moves fast into mixers, cross-chain bridges, or high-volume exchange deposit addresses is optimising for laundering speed and accepting some loss to fees and slippage. An attacker who sits on nine figures of tainted coin is doing something else: either waiting for attention to fade, lacking off-ramp capacity for that size, or facing a market where every major venue has already flagged the address cluster.
For victims, static coins are the best of a bad set of outcomes. Traceable and unmoved leaves open the possibility of civil recovery, exchange freezes at the point of eventual cash-out, or negotiated return. It is not a good position. It is a better one than watching the flow disappear into a privacy pool within an hour.
The Second-Order Effect on Custody
The exploit has reopened the self-custody argument in an uncomfortable way. The standard case for hardware wallets is that they remove counterparty risk. What this incident demonstrates is that they replace it with supply chain and firmware risk, which is harder for a non-technical holder to evaluate and impossible to audit after the fact.
On-chain flow in the days following the first wave showed a measurable move of Bitcoin back onto exchanges, an inversion of the usual post-incident pattern where holders withdraw to cold storage. Around 39,600 BTC moved in a single day during the aftermath, the largest daily migration since the FTX collapse. Some portion of that was affected users consolidating to safety, and some was almost certainly unaffected users deciding that a regulated custodian looked better than a device they could no longer independently verify.
What to Do If You Hold a Coldcard
- Check your device's original firmware build date, not the current installed version
- If the device was initialised on any build from the affected period, treat the seed as compromised regardless of whether funds have moved
- Generate a new seed on patched firmware and sweep to fresh addresses
- Verify the new receiving addresses on the device screen, not on the host machine
- If funds were already taken, report to Galaxy's victim tracing effort so the address cluster stays documented
The uncomfortable lesson is that the failure was invisible for five years. Nothing about an affected device looked wrong. The wallet worked, signed correctly, and produced valid addresses. The only defect was in a number nobody could see.
Whatever you decide about hardware wallets after this, the discipline that helps most is knowing exactly which addresses hold what, across which devices, at all times. A portfolio you can enumerate is one you can audit and move quickly. A portfolio spread across devices you last touched in 2021 is not.
Koinlytics