The Bitcoin Beacon The Bitcoin Beacon
Network & Mining · Toronto

Investigators Race to Trace $116 Million in Stolen Bitcoin

The breach that emptied Coldcard wallets has grown to roughly 1,800 coins — and the fight has shifted from patching devices to chasing the money before it disappears.

By The Bitcoin Beacon · TORONTO, Canada · August 6, 2026 · 6 min read
A forensic analyst traces branching bitcoin transaction lines across a wall chart beside an opened hardware wallet, linocut
Network & Mining · The hunt for the Coldcard coins — Illustration: The Bitcoin Beacon

A week after a firmware flaw turned thousands of Coldcard hardware wallets into open safes, the story has stopped being about the bug and started being about the chase. The amount stolen keeps climbing, the list of victims keeps growing, and a handful of investigators are now racing to follow the coins before the thieves can launder them out of reach.

As of this week, an attacker — or, more likely, several — has moved roughly 1,800 bitcoin, about $116 million, out of more than 5,200 addresses generated on Coldcard devices since July 30. The first wave was brutal and fast: 1,196 addresses drained in 41 minutes, more than 1,000 coins gone before most owners knew anything was wrong. Later waves have gone after smaller balances using more complex, harder-to-trace transaction patterns.

One bug, many thieves

The root cause is the one The Bitcoin Beacon reported last week: a firmware version shipped in March 2021 quietly skipped the device’s dedicated hardware randomness chip and fell back to a predictable software substitute. Any key generated in that state was guessable. What has become clear since is that the vulnerability is now being exploited by more than one group — security researchers count at least a dozen distinct actors picking at the same wound, which is why the losses keep arriving in waves rather than a single sweep.

That plurality matters. A lone thief can be tracked as one behavior; a dozen independent ones, some racing each other to drain the same weak keys, make the forensic picture messier and the clean-up slower.

About 90% of the stolen coins still haven’t moved — the whole recovery hinges on that number.

Following the money

The recovery effort is being led, for now, by the digital-asset firm Galaxy, which says it is working with dozens of individual victims to trace their coins. Its most important claim is a hopeful one: roughly 90% of the stolen bitcoin remains static and traceable, sitting in addresses the thieves have not yet cashed out. Galaxy says it has supplied around 600 suspected attacker addresses, plus confirmed victim addresses, to U.S. federal law enforcement, cryptocurrency exchanges, and compliance firms.

That is the whole game. Bitcoin’s ledger is public, so stolen coins can be watched in real time; the thieves’ problem is converting them to spendable money without passing through an exchange that has been warned. As long as 90% of the haul stays parked, the coins are visible hostages. The moment they move toward a fiat off-ramp, the exchanges on that list of addresses decide whether to freeze them.

No one is being made whole

The company that makes Coldcard, Coinkite, has said its investigation is ongoing and that a full technical review will follow. It is helping affected users file police reports and insurance claims. What it has pointedly not done is offer to compensate anyone. There is no reimbursement fund, no promise to cover the losses — a stance that has drawn anger from victims who followed self-custody best practices to the letter and still watched their savings vanish. One, quoted by Forbes, summed up the mood: he had done everything right, and it did not matter.

Coinkite’s defenders note that the affected firmware is five years old, that fixes have shipped for every device line, and that a seed generated on a patched device is safe. But that is cold comfort to holders whose keys were already weak: no update can un-guess a private key, and the only real fix for an exposed wallet is to generate a fresh one and move the coins — which, for the drained, is too late.

What to watch

Three things will decide how this ends. Whether that 90% figure holds, or the thieves find willing exchanges and the traceable pile shrinks. Whether law enforcement, armed with Galaxy’s address list, can freeze or claw back any material amount — a rare outcome even for well-traced thefts. And whether the episode pushes the wider industry toward routine, independent audits of the open-source firmware that secures billions in self-custodied bitcoin. The lesson of the past week is not that self-custody failed; custodians have their own single points of failure. It is that a bearer asset rewards paranoia, and that reading the code is now part of the job.

Why it matters: bitcoin’s transparency is the victims’ best weapon — the coins can be watched, but only frozen if the thieves try to spend them.

Sources

  1. Forbes — “I Did Everything Right”: Warning After $116 Million Bitcoin Hack
  2. CoinDesk — Bitcoin Cold-Wallet Attack Spreads to 4,500 Addresses as Losses Near $89 Million
  3. The Crypto Times — Coldcard Hack Losses Hit $100M With 1,596 BTC Stolen in Ongoing Attack
  4. TheStreet — Update: Coldcard Hack Grows, Call Your Friends
  5. The Bitcoin Beacon — A Firmware Bug Drained $38 Million From Coldcard Wallets

Editor’s note: loss estimates are preliminary and were still rising at press time; figures range from roughly $89M to $130M across sources as the attack continues. Recovery and tracing claims are Galaxy’s. Nothing here is financial advice.

The world’s bitcoin headlines, in your inbox every morning.

Free. Five minutes. No hype.

Subscribe free