Galaxy Research traced 1,789.28 Bitcoin from 8,865 addresses to the Coldcard exploit, with 87.3% of funds still in attacker-controlled wallets.
Galaxy Research traced 1,789.28 Bitcoin from 8,865 addresses to the Coldcard exploit, with 87.3% of funds still in attacker-controlled wallets.

Galaxy Research traced 1,789.28 Bitcoin from 8,865 addresses to the Coldcard exploit, worth $114.7 million at theft, with 87.3% of funds unmoved.
The same Bitcoin is now worth about $138.8 million at current prices, Alex Thorn, Galaxy's head of firmwide research, said in an X post Monday.
Across the 8,865 identified addresses, the median loss was 0.00152 BTC and the average stood at 0.20184 BTC. Affected wallets had been dormant for a median of 3.2 years before the theft. Galaxy has received 221 victim reports covering 790.72 BTC, or 44.2% of the total attributed losses, with a median reported loss of 1.04272 BTC — meaning more than half of reporting victims lost at least 1 Bitcoin.
Including medium-confidence addresses would push the total to about 1,824 BTC, or roughly $140 million at the time of the respective thefts. TRM Labs separately estimated losses at approximately 1,816 BTC, leaving the final tally subject to further attribution as investigators identify additional affected addresses.
The thefts began July 30 and stem from a flaw in Coldcard's seed-generation process. Galaxy's research found that a firmware change introduced in March 2021 caused affected devices to fall back on an inadequate source of entropy when generating wallet seeds, reducing the effective randomness of some seeds. That allowed attackers to generate candidate keys and identify corresponding Bitcoin addresses without physical access to the devices. The vulnerability affected certain Coldcard-generated wallets rather than Bitcoin's underlying cryptography or consensus rules.
All Bitcoin tied to the first three identified attack waves has remained unmoved, giving researchers an onchain record of where a large portion of the stolen funds is being held. Some funds from later attacks have started moving through CoinJoin transactions, peel chains and other obfuscation methods designed to make the movement harder to follow, Thorn said.
Galaxy has shared identified attacker addresses with cryptocurrency exchanges, compliance companies and law enforcement in an effort to identify or freeze funds if they reach centralized intermediaries. The firm has identified at least 33 additional footprints beyond the major attack waves but could not establish whether all belonged to the same attacker.
No confirmed attacker activity has been identified after Aug. 6, although victims continued to come forward and provide information that helped researchers attribute additional losses. Galaxy cautioned that the apparent slowdown could reflect the migration of vulnerable funds or the fact that many exposed balances had already been drained.
The incident has put attention on a hardware wallet brand built specifically around Bitcoin self-custody. Coinkite released the Coldcard MK5 in May, its first hardware revision to the flagship MK line since the MK4 arrived in 2022, retaining a dual secure-element design and air-gapped transaction workflows.
Weak randomness can become especially dangerous in cryptocurrency wallets because seed phrases ultimately determine the private keys controlling the assets. If the random input used to create a seed contains too little entropy, an attacker with enough computing resources may be able to search the reduced range of possible combinations. TRM Labs said installing updated firmware does not repair a seed originally created with weak randomness, meaning affected users would need to generate a new seed on secure hardware and transfer their Bitcoin to addresses derived from it.
The lack of movement across the first three waves is particularly important to the tracing effort because the corresponding Bitcoin has not yet passed through the obfuscation techniques observed in later activity. Researchers can therefore continue monitoring known addresses for outgoing transactions.
Earlier in August, TRM Labs also reported that most stolen funds were pooling in a limited number of attacker-controlled addresses with little onward movement at the time. Differences between transaction structures across the attack waves led the company to say multiple attackers could have been involved, although it did not attribute the exploit to any specific actor.
For investigators, the stolen Bitcoin itself remains the main source of evidence. Galaxy has continued distributing confirmed attacker addresses to exchanges, compliance firms and law enforcement while monitoring the 1,561 BTC that has yet to leave attacker-controlled collection and holding wallets.
This article is for informational purposes only and does not constitute investment advice.