The breach that emptied Coldcard wallets has grown to roughly 1,800 coins — and the fight has shifted from patching devices to chasing the money before it disappears.
A week after a firmware flaw turned thousands of Coldcard hardware wallets into open safes, the story has stopped being about the bug and started being about the chase. The amount stolen keeps climbing, the list of victims keeps growing, and a handful of investigators are now racing to follow the coins before the thieves can launder them out of reach.
As of this week, an attacker — or, more likely, several — has moved roughly 1,800 bitcoin, about $116 million, out of more than 5,200 addresses generated on Coldcard devices since July 30. The first wave was brutal and fast: 1,196 addresses drained in 41 minutes, more than 1,000 coins gone before most owners knew anything was wrong. Later waves have gone after smaller balances using more complex, harder-to-trace transaction patterns.
The root cause is the one The Bitcoin Beacon reported last week: a firmware version shipped in March 2021 quietly skipped the device’s dedicated hardware randomness chip and fell back to a predictable software substitute. Any key generated in that state was guessable. What has become clear since is that the vulnerability is now being exploited by more than one group — security researchers count at least a dozen distinct actors picking at the same wound, which is why the losses keep arriving in waves rather than a single sweep.
That plurality matters. A lone thief can be tracked as one behavior; a dozen independent ones, some racing each other to drain the same weak keys, make the forensic picture messier and the clean-up slower.
The recovery effort is being led, for now, by the digital-asset firm Galaxy, which says it is working with dozens of individual victims to trace their coins. Its most important claim is a hopeful one: roughly 90% of the stolen bitcoin remains static and traceable, sitting in addresses the thieves have not yet cashed out. Galaxy says it has supplied around 600 suspected attacker addresses, plus confirmed victim addresses, to U.S. federal law enforcement, cryptocurrency exchanges, and compliance firms.
That is the whole game. Bitcoin’s ledger is public, so stolen coins can be watched in real time; the thieves’ problem is converting them to spendable money without passing through an exchange that has been warned. As long as 90% of the haul stays parked, the coins are visible hostages. The moment they move toward a fiat off-ramp, the exchanges on that list of addresses decide whether to freeze them.
The company that makes Coldcard, Coinkite, has said its investigation is ongoing and that a full technical review will follow. It is helping affected users file police reports and insurance claims. What it has pointedly not done is offer to compensate anyone. There is no reimbursement fund, no promise to cover the losses — a stance that has drawn anger from victims who followed self-custody best practices to the letter and still watched their savings vanish. One, quoted by Forbes, summed up the mood: he had done everything right, and it did not matter.
Coinkite’s defenders note that the affected firmware is five years old, that fixes have shipped for every device line, and that a seed generated on a patched device is safe. But that is cold comfort to holders whose keys were already weak: no update can un-guess a private key, and the only real fix for an exposed wallet is to generate a fresh one and move the coins — which, for the drained, is too late.
Three things will decide how this ends. Whether that 90% figure holds, or the thieves find willing exchanges and the traceable pile shrinks. Whether law enforcement, armed with Galaxy’s address list, can freeze or claw back any material amount — a rare outcome even for well-traced thefts. And whether the episode pushes the wider industry toward routine, independent audits of the open-source firmware that secures billions in self-custodied bitcoin. The lesson of the past week is not that self-custody failed; custodians have their own single points of failure. It is that a bearer asset rewards paranoia, and that reading the code is now part of the job.
Why it matters: bitcoin’s transparency is the victims’ best weapon — the coins can be watched, but only frozen if the thieves try to spend them.
Editor’s note: loss estimates are preliminary and were still rising at press time; figures range from roughly $89M to $130M across sources as the attack continues. Recovery and tracing claims are Galaxy’s. Nothing here is financial advice.
Free. Five minutes. No hype.
Subscribe free