The global cryptocurrency community is facing a significant security crisis as a long-dormant vulnerability in Coldcard hardware wallets has transitioned into an active, large-scale drain of assets. Galaxy Research reported on Saturday that it has identified a third wave of programmatic thefts targeting Bitcoin holders who used specific versions of Coinkite’s Coldcard devices. According to the latest data, the total amount of stolen Bitcoin has reached approximately 1,367 BTC, valued at roughly $88.6 million at current market prices. The exploit, which stems from a critical firmware error dating back to 2021, has already compromised 4,585 individual blockchain addresses, and researchers warn that the attacker’s reach is likely to expand until every vulnerable device is emptied.
The situation has reached a critical juncture, prompting urgent warnings from security analysts and industry leaders. Alex Thorn, Head of Research at Galaxy, has been at the forefront of tracking the on-chain movement of these stolen funds. He characterized the attack as "ongoing" and "deliberate," noting that the latest wave alone saw the drainage of 207.73 BTC. The methodology of the attacker appears to be highly sophisticated, utilizing automated scripts to identify and sweep funds from addresses generated with insufficient entropy. Galaxy Research has already flagged approximately 600 suspected attacker addresses, sharing this data with federal investigators, blockchain compliance firms, and cross-industry cybercrime units in an effort to blacklist the stolen funds and track their eventual movement to exchanges.
The Root Cause: A Critical Failure in Entropy
The origins of this multi-million dollar exploit can be traced back to a specific firmware build error released by Coinkite in March 2021. In the world of hardware wallets, security is predicated on "entropy"—the measure of randomness used to generate a 12 or 24-word seed phrase. This seed phrase is the master key from which all private keys for a wallet are derived. Under normal circumstances, the mathematical probability of two people generating the same seed phrase is virtually zero.
However, the March 2021 firmware update for Coldcard devices contained a flaw that severely limited the randomness of the seed generation process. Instead of drawing from a nearly infinite pool of possibilities, the affected devices generated seed phrases from a much smaller, predictable subset. This "weak entropy" made the resulting private keys susceptible to brute-force attacks. While the flaw remained largely theoretical for several years, the current wave of thefts suggests that an attacker—or a group of attackers—has successfully reverse-engineered the flawed generation process to pre-calculate the resulting keys.
Security researchers, including Thorn, have speculated that the speed and efficiency of the current sweeps suggest the use of Large Language Models (LLMs) or specialized AI tools to facilitate the cracking of these weakened seeds. By using programmatic methods, the attackers can scan the Bitcoin blockchain for any address that matches the "weak" mathematical signature of the 2021 firmware and move the funds almost instantly.
Chronology of the Exploit and the Three Waves of Theft
The timeline of the Coldcard exploit reveals a slow-burning disaster that has only recently accelerated into a full-scale crisis.
- March 2021: Coinkite releases a firmware update for Coldcard hardware wallets. A build error within this update compromises the entropy of the seed generation process for single-signature wallets.
- 2021 – Mid-2025: The vulnerability remains largely unnoticed by the broader public. During this period, long-term investors continue to "HODL" their Bitcoin on these addresses, unaware that their private keys are mathematically guessable.
- Late 2025 – Early 2026: Initial reports of "ghost" transactions begin to surface in niche security forums. Small amounts of Bitcoin are moved from dormant wallets, but the scale remains limited.
- July 2026: The first major "wave" of thefts is identified. Galaxy Research and other on-chain analysts observe a sudden spike in sweeps targeting Coldcard-generated addresses.
- July 29, 2026: A massive coordinated sweep occurs. High-profile victims, including Canadian coach Jonathan Goodman, lose significant holdings within minutes. Goodman reported the loss of 18.25 BTC ($1.6 million CAD) in a seven-minute window.
- August 2, 2026: Galaxy Research confirms the "Third Wave" of the attack. Alex Thorn issues an emergency alert on social media, revealing that the total stolen amount has surpassed 1,367 BTC.
The data reveals a haunting trend: the average dormancy of the stolen coins was 3.18 years. This indicates that the victims were not active traders, but rather long-term "cold storage" users who believed their assets were safely tucked away in offline devices.
Impact on Victims and the Self-Custody Ethos
The human cost of the exploit is substantial. For many victims, the stolen Bitcoin represented years of savings or retirement funds. Jonathan Goodman’s case has become a focal point for the community’s frustration. Goodman, who kept his Coldcard and its physical backup in a safety deposit box that never touched the internet, expressed a sentiment shared by many: "I did everything right."
This exploit strikes at the heart of the "Not your keys, not your coins" philosophy that has defined the Bitcoin movement for over a decade. The industry has long advocated for self-custody as the gold standard of security, urging users to move their assets off centralized exchanges to avoid the risks of platform insolvency or hacking. However, the Coldcard flaw demonstrates that even hardware wallets—the supposed peak of security—are subject to human error at the manufacturing and software development levels.
In a striking reversal of traditional crypto wisdom, security experts are now advising affected users to move their funds back to centralized exchanges like Coinbase or Binance, or to freshly generated addresses on different hardware platforms, until the threat is neutralized. This "flight to safety" highlights a temporary loss of faith in self-custody solutions for those using the compromised firmware.
Technical Analysis of the Attacker’s Behavior
Analysis of the on-chain data shows that the attacker is not yet attempting to "wash" or liquidate the funds. Currently, the 1,367 BTC remains parked across thousands of attacker-controlled addresses. This "parked" status is common in high-profile hacks where the attacker knows that every movement is being tracked by firms like Chainalysis and Elliptic.
The programmatic nature of the attack is particularly concerning. Thorn noted that the sweeps appear to be executed by a script that monitors the mempool (the waiting area for Bitcoin transactions). As soon as a vulnerable address is identified or an attempt is made to move funds from one, the attacker can potentially outbid the user with a higher transaction fee to ensure the stolen transaction is processed first—a technique known as "front-running."
Furthermore, the focus on single-signature (single-sig) wallets is a key detail. Multi-signature (multi-sig) setups, which require more than one private key to authorize a transaction, appear to be unaffected by this specific entropy flaw. This is because a multi-sig setup usually involves keys generated at different times or on different devices, making it mathematically impossible for a single firmware flaw to compromise the entire wallet.
Official Responses and Industry Fallout
Coinkite, the manufacturer of Coldcard, has faced intense scrutiny regarding the 2021 build error. While the company has released subsequent firmware updates that corrected the entropy issue, the problem remains that any seed phrase generated during the period of the flaw is permanently compromised. Updating the firmware now does not change the fact that the underlying seed phrase is weak; the only solution is for users to generate an entirely new seed phrase on a secure build and transfer their assets.
Regulatory bodies are also beginning to take notice. In Canada, Jonathan Goodman has filed reports with the Ontario Securities Commission (OSC) and local law enforcement. In the United States, Galaxy Research has shared its database of 600 attacker addresses with federal investigators. The scale of the loss—approaching $90 million—elevates this from a technical glitch to a major financial crime investigation.
The broader cryptocurrency industry is now grappling with the implications of this event. Industry leaders, including former Binance CEO Changpeng Zhao (CZ), have amplified the warnings, urging Bitcoin holders to check their wallet generation dates. The event has sparked a renewed debate over the "open source" nature of hardware wallet code. While Coldcard’s code is viewable, the specific "build error" in the compiled firmware was not immediately obvious to casual observers, leading to calls for more rigorous third-party audits of hardware wallet releases.
Guidance for Bitcoin Holders
For users of Coldcard devices, the window of opportunity to secure funds is closing. Galaxy Research and other security firms have issued the following recommendations:
- Identify Generation Date: Any single-signature wallet generated on a Coldcard device between March 2021 and the release of the corrected firmware (later in 2021) should be considered compromised.
- Immediate Migration: Users should not wait for a "wave" to hit their specific address. Funds should be moved immediately to a new wallet with a seed phrase generated on a known-secure device or a different hardware brand.
- Utilize Multi-Sig: For significant holdings, security experts recommend moving from single-sig to multi-sig configurations, which provide a layer of redundancy against firmware-specific vulnerabilities.
- Avoid Reusing Seeds: Under no circumstances should a user "restore" a compromised seed phrase onto a new device. The seed itself is the point of failure.
- Temporary Exchange Custody: If a user does not have access to a new, secure hardware wallet immediately, moving funds to a reputable, regulated centralized exchange is a viable short-term measure to prevent programmatic drainage.
As the investigation continues, the focus remains on mapping the attacker’s infrastructure and preventing further losses. With $88.6 million already gone and the attack still active, the Coldcard exploit stands as one of the most significant security failures in the history of Bitcoin self-custody. The coming weeks will be telltale as to whether law enforcement can successfully track the "parked" funds or if the attacker will find a way to obfuscate and exit with nearly $90 million in stolen digital gold.







