Galaxy Research revised the Coldcard exploit tally Saturday to 1,719 BTC — roughly $111 million — as a five-year-old firmware flaw continues to generate new victim reports, with the revised tally expected to climb further.
- Galaxy Research confirmed 1,719 BTC ($111M) stolen in the ongoing Coldcard exploit, with total losses projected to exceed $130M.
- A March 2021 firmware defect cut seed entropy from 128 to ~72 bits, letting attackers reconstruct keys without physical device access.
- 250+ victims have filed reports with Galaxy Research; at least 15 distinct threat actors have been identified across three attack waves.
Lead
Galaxy Research on Saturday, August 8, raised its confirmed Coldcard exploit figure to 1,719 BTC, or approximately $111 million at current prices, following a new batch of victim disclosures. The research group flagged total losses — including wallets not yet fully documented — as likely surpassing $130 million, making the incident the largest hardware wallet breach on record and the third-largest crypto theft of 2026. The number of individuals who have contacted Galaxy directly now exceeds 250 victims, spanning retail holders across multiple continents.
What Happened
The root cause is a build-configuration error in a Coinkite firmware update shipped March 17, 2021. Devices running affected versions — 4.0.1 through 4.1.9 on the Coldcard Mk3, Mk4, Mk5, and Q lines — silently substituted a software random-number generator for the hardware entropy source during seed creation. The result: recovery seeds carrying roughly 72 bits of effective randomness rather than the 128 bits the design specified. Attackers precomputed the truncated keyspace offline, requiring no physical access to a device once the seed generation window was identified on-chain.
The exploit unfolded in three documented waves. On July 30, within 41 minutes, roughly 1,083 BTC was swept from 1,196 addresses, a pace that pointed to full automation. Subsequent waves through August 3 brought the observed tally to approximately 1,367 BTC across 4,585 addresses. Saturday's revised tally of 1,719 BTC incorporates new address clusters linked to the same seed-entropy flaw and victim-reported transaction IDs submitted through Galaxy's disclosure portal.
Attack Profile
Galaxy Research has identified at least 15 distinct threat actors operating independently within the same exploitable keyspace. The fragmented attacker structure — more than 25 documented attack patterns — suggests the precomputed seed tables circulated beyond a single group after the vulnerability became known. Victim profiles skew toward everyday Bitcoin holders rather than institutional custodians, consistent with the retail market segment that adopted Coldcard Mk4 and Mk5 hardware in 2021–2023.
Industry Response
Coinkite moved to deprecate affected firmware builds and publicly urged users to sweep funds to wallets generated on unaffected hardware or clean software implementations. On-chain messaging to attacker-controlled addresses from distressed holders has been visible across several Bitcoin block explorers. A community-organized reimbursement pool, proposed by Stacks co-founder Muneeb Ali, would allow Bitcoin holders to purchase victim claims at face value, though the initiative remains in early coordination.Security researchers at TRM Labs confirmed the exploit vectors align with known weak-entropy attack methodologies documented in academic literature since 2018, noting that the five-year gap between firmware release and active exploitation likely reflects time needed to build sufficiently complete precomputed tables.
Outlook
Galaxy Research has indicated additional victim clusters remain under analysis, and Saturday's 1,719 BTC figure is likely to see further upward revisions as the disclosure window remains open. The broader hardware wallet sector now faces intensified scrutiny of entropy-sourcing architecture, with independent auditors calling for mandatory entropy-validation routines in future firmware certification standards. Regulatory bodies in the European Union and the United Kingdom are monitoring the incident for potential implications under digital-asset consumer protection frameworks currently under legislative review.





