Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Is Bitcoin protected by the First Amendment as Michael Saylor says?

    August 25, 2026

    Coldcard hackers leave 87% of stolen Bitcoin unmoved after $114M theft

    August 25, 2026

    Italian giant UniCredit eyes Commerzbank with German crypto ties

    August 25, 2026
    Facebook X (Twitter) Instagram
    Block Buzz News
    • Bitcoin
    • Coinbase
      • Litecoin
      • Altcoins
    • Blockchain
    • Crypto
    • Ethereum
    • Lithosphere News Releases
    Facebook X (Twitter) Instagram YouTube
    Block Buzz News
    Home » Coldcard hackers leave 87% of stolen Bitcoin unmoved after $114M theft
    Crypto

    Coldcard hackers leave 87% of stolen Bitcoin unmoved after $114M theft

    James WilsonBy James WilsonAugust 25, 2026No Comments7 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email



    More than 87% of the Bitcoin attributed to the Coldcard hack has remained unmoved, leaving 1,561 BTC under attacker control after researchers linked the exploit to $114.7 million in losses.

    Summary

    • Galaxy Research traced 1,789 BTC stolen from 8,865 addresses to the Coldcard hack.
    • About 1,561 BTC, or 87.3% of the attributed losses, remains unmoved.
    • Some Bitcoin from later attacks has moved through CoinJoin transactions and peel chains.
    • Galaxy has shared identified attacker addresses with exchanges, compliance firms and law enforcement.

    Galaxy Research has traced 1,789.28 BTC stolen from 8,865 addresses to the Coldcard exploit, according to a Monday X post from Alex Thorn, the firm’s head of research. The Bitcoin was worth $114.7 million when it was taken, while Thorn put its current value at about $138.8 million.

    📊 updated numbers on coldcard exploit

    8865 addresses lost 1789.28 BTC worth $114.7m at the time of theft ($138.8m today)

    – loss by address
    median 0.00152
    mean 0.20184
    dormancy median 3.2yr
    dormancy mean 3.6yr

    – loss by victim reports (221)
    median 1.04272
    mean 3.57792
    dormancy… pic.twitter.com/d2R29dYyco

    — Alex Thorn (@intangiblecoins) August 24, 2026

    Of the total, 1,561 BTC, or 87.3%, has not been spent and remains in collection or holding addresses controlled by the attackers. All Bitcoin tied to the first three identified attack waves has also remained unmoved, giving researchers an onchain record of where a large portion of the stolen funds is being held.

    Some funds from later attacks have started moving. Thorn said attackers have used CoinJoin transactions, peel chains and other methods designed to make the movement of Bitcoin harder to follow across addresses.

    Most Bitcoin from the Coldcard hack remains traceable

    Galaxy’s latest figures include both address-level analysis and information submitted directly by victims as researchers continue mapping wallets connected to the exploit.

    Across the 8,865 addresses identified by the firm, the median loss was 0.00152 BTC and the average stood at 0.20184 BTC, according to figures shared by Thorn. The affected Bitcoin had also remained dormant for long periods before being stolen, with median address dormancy of 3.2 years and an average of 3.6 years.

    Victim reports show heavier losses on an individual basis. Galaxy has received 221 reports covering 790.72 BTC, equivalent to 44.2% of the total Bitcoin attributed to the exploit. The median reported loss was 1.04272 BTC and the average was 3.57792 BTC.

    Thorn clarified separately that the median means at least half of the 221 reporting victims lost 1 BTC or more. Bitcoin covered by those reports had remained dormant for a median of 3.25 years before the theft, while the average dormancy period was 2.99 years.

    The confirmed tally may not account for every loss linked to the incident. Thorn said that including medium-confidence addresses not yet confirmed would increase the estimate to about 1,824 BTC, worth roughly $140 million at the time of the respective thefts.

    Earlier estimates changed as researchers identified additional victim addresses and attack patterns. TRM Labs said on Aug. 5 that the incident had involved several waves beginning July 30 and traced the thefts to a firmware problem that weakened the randomness used when generating some Coldcard wallet seeds.

    According to TRM Labs, a build configuration error introduced through firmware in March 2021 caused affected devices to fall back on a weaker software random number generator instead of relying fully on hardware-generated entropy. The security firm said the resulting key strength could fall low enough for private keys to be recovered through brute-force computing without physical access to the wallet.

    Attackers have started obscuring some later thefts

    While the largest holdings remain parked, Galaxy has found different transaction behavior among funds taken during later attacks.

    CoinJoin can combine transactions from multiple participants to make it more difficult to connect individual inputs with their eventual outputs. Peel chains involve repeatedly moving smaller amounts from a larger balance into new addresses, creating longer transaction trails for investigators to follow.

    Galaxy has continued tracking those movements while sharing identified attacker addresses with cryptocurrency exchanges, compliance companies and law enforcement. Thorn said the effort could allow centralized platforms to identify and potentially freeze stolen Bitcoin if attackers eventually send funds into services where accounts or transactions can be intercepted.

    The lack of movement across the first three waves is particularly important to the tracing effort because the corresponding Bitcoin has not yet passed through the obfuscation techniques observed in later activity. Researchers can therefore continue monitoring known addresses for outgoing transactions.

    Earlier in August, TRM Labs also reported that most stolen funds were pooling in a limited number of attacker-controlled addresses with little onward movement at the time. Differences between transaction structures across the attack waves led the company to say multiple attackers could have been involved, although it did not attribute the exploit to any specific actor.

    Coldcard security had focused on offline key storage

    The incident has put attention on a hardware wallet brand built specifically around Bitcoin self-custody.

    In May, crypto.news previously reported that Coinkite had released the Coldcard MK5, its first hardware revision to the flagship MK line since the MK4 arrived in 2022. The device retained a dual secure-element design using components from two chip manufacturers and continued supporting air-gapped transaction workflows.

    The MK5 also introduced a larger Gorilla Glass display, redesigned physical buttons and improved NFC functionality. Coinkite said at the time that the device continued using open-source firmware while keeping its Bitcoin-only design.

    Wallet security had already faced increased attention before the Coldcard losses surfaced. In July, Coinspect disclosed a weakness it called “Ill Bloom,” which involved poor randomness during recovery-phrase generation across several software wallets. The security company said about $5 million had moved from exposed wallets by early July, although hardware wallets appeared unaffected by that particular issue.

    Weak randomness can become especially dangerous in cryptocurrency wallets because seed phrases ultimately determine the private keys controlling the assets. If the random input used to create a seed contains too little entropy, an attacker with enough computing resources may be able to search the reduced range of possible combinations.

    Hardware wallet risks have drawn fresh scrutiny

    Other wallet security incidents this summer have involved different attack methods.

    Ledger’s Donjon researchers in July demonstrated a laser attack against a Tangem wallet card that could reset its password and potentially allow transactions to be signed. Tangem said the method required physical possession of the card, specialist knowledge and laboratory equipment costing around $250,000, making the attack different from a remotely exploitable wallet weakness.

    Onchain investigator ZachXBT had also criticized hardware wallets in July, saying he did not consider existing devices suitable for signing critical transactions or holding large amounts of cryptocurrency. His comments represented a personal assessment and were not tied to evidence of a new hardware compromise at the time.

    The Coldcard incident involves a different failure point because researchers linked the thefts to seed generation on affected devices. TRM Labs said installing updated firmware does not repair a seed that was originally created with weak randomness, meaning users with affected wallets would need to generate a new seed on secure hardware and transfer their Bitcoin to addresses derived from it.

    For investigators, the stolen Bitcoin itself remains the main source of evidence. Galaxy has continued distributing confirmed attacker addresses to exchanges, compliance firms and law enforcement while monitoring the 1,561 BTC that has yet to leave attacker-controlled collection and holding wallets.





    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    James Wilson

    Related Posts

    Fortune Protocol integrates Polymarket liquidity into Fortune Markets

    August 25, 2026

    Gemini enables XRP transfers via XRPL in Singapore

    August 25, 2026

    BNB Chain activates Pasteur hard fork on mainnet

    August 25, 2026

    Bitcoin bull market underway, Arthur Hayes says

    August 25, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Announcing the Ethereum Season of Internships

    June 26, 2026

    Binance to stop serving EU clients after missing MiCA licence deadline

    June 26, 2026

    Ethereum University Tour | Ethereum Foundation Blog

    June 26, 2026

    Checkpoint #2: Apr 2025 | Ethereum Foundation Blog

    June 26, 2026
    Don't Miss
    Coinbase

    Is Bitcoin protected by the First Amendment as Michael Saylor says?

    By John SmithAugust 25, 2026

    Michael Saylor and dozens of Bitcoiners have endorsed a new report claiming that bitcoin is…

    Coldcard hackers leave 87% of stolen Bitcoin unmoved after $114M theft

    August 25, 2026

    Italian giant UniCredit eyes Commerzbank with German crypto ties

    August 25, 2026

    Fortune Protocol integrates Polymarket liquidity into Fortune Markets

    August 25, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us

    BlockBuzzNews: Your daily dose of the latest in cryptocurrency trends, insights, and updates!

    Our Picks

    Is Bitcoin protected by the First Amendment as Michael Saylor says?

    August 25, 2026

    Coldcard hackers leave 87% of stolen Bitcoin unmoved after $114M theft

    August 25, 2026

    Italian giant UniCredit eyes Commerzbank with German crypto ties

    August 25, 2026
    Most Popular

    Announcing the Ethereum Season of Internships

    June 26, 2026

    Binance to stop serving EU clients after missing MiCA licence deadline

    June 26, 2026

    Ethereum University Tour | Ethereum Foundation Blog

    June 26, 2026

    Type above and press Enter to search. Press Esc to cancel.