The Coldcard exploit is ongoing, with Galaxy Analysis now monitoring about $88.6 million stolen throughout 4,585 addresses in three waves.
Galaxy’s Alex Thorn described the sweeps as deliberate and certain LLM-orchestrated, warning that each single-sig Coldcard handle created after the March 2021 firmware flaw will ultimately be drained.
The breach has spurred an uncommon reversal of the “not your keys, not your cash” ethos as customers transfer Bitcoin again to exchanges.
The theft of Bitcoin from compromised Coldcard {hardware} wallets remains to be underway, with researchers now monitoring losses of roughly $88 million and warning that each susceptible gadget will ultimately be emptied.
Galaxy Analysis stated Saturday it has recognized a 3rd wave of thefts, through which 207.73 BTC was drained, lifting its noticed tally to about 1,367 BTC—round $88.6 million—throughout 4,585 addresses. The agency referred to as the exploit ongoing and urged anybody holding single-signature funds on a Coldcard to maneuver them without delay. Galaxy stated it has flagged roughly 600 suspected attacker addresses to federal investigators, compliance corporations and cross-industry cyber investigators, crediting victims who shared transaction particulars for serving to map the on-chain patterns.
“I proceed to research and add new Coldcard sufferer and attacker addresses to our investigation database,” Galaxy’s head of analysis Alex Thorn posted to X. “The assault is ongoing—transfer your funds off Coldcard-generated addresses instantly in case you have not achieved so.”
i proceed to research and add new Coldcard sufferer and attacker addresses to our investigation database tonight
THE ATTACK IS ONGOING — transfer your funds off Coldcard-generated addresses instantly in case you have not achieved so. i’ll present extra updates on estimated…
— Alex Thorn (@intangiblecoins) August 2, 2026
The flaw, as Decrypt beforehand reported, stems from a March 2021 firmware construct error on Coinkite’s units that induced seed phrases to be generated with far too little randomness, leaving personal keys guessable. Thorn wrote that the sweeps look deliberate and programmatic, most likely orchestrated with a big language mannequin, and cautioned that each single-sig Coldcard handle created after that 2021 replace will ultimately be drained, saying it is just a matter of time.
Thorn famous the stolen cash had sat untouched for years earlier than being taken—a median dormancy of three.18 years—underscoring that the victims had been long-term holders. The funds from the three documented waves stay parked in attacker addresses and haven’t moved.
The fallout has pushed a panicked response from affected customers, with safety specialists urging warning when transferring funds to new addresses. Most of the affected customers are racing to maneuver Bitcoin off self-custody and again onto centralized crypto exchanges, corresponding to Coinbase or Binance, or freshly generated addresses—an inversion of the {industry}’s traditional “not your keys, not your cash” ethos.
$1.6 million {dollars} in Bitcoin was drained from my account on July twenty ninth within the Chilly Card pockets hack.
My Bitcoin was in chilly storage. My keys had been on a ColdCard gadget saved in a security deposit field that had by no means been related to the web.
— Jonathan Goodman 🇨🇦 (@itscoachgoodman) August 1, 2026
For some, the warnings got here too late. Canadian coach Jonathan Goodman stated in a publish on X that 18.25 BTC, value about $1.6 million Canadian, was swept from his wallets in a seven-minute span on July 29, regardless of his keys sitting in a security deposit field that by no means touched the web. “Maybe the toughest half about that is that I did all the pieces proper,” he wrote, including that he’s submitting studies with police and the Ontario Securities Fee.
Day by day Debrief Publication
Begin on daily basis with the highest information tales proper now, plus unique options, a podcast, movies and extra.