Galaxy Research says as much as 2,055 Bitcoin may have been stolen through a vulnerability in Coldcard hardware wallets, with potential losses estimated at nearly $130m.
The firm has confirmed the theft of 1,596 BTC from 7,300 addresses across three attack waves, as well as 14 smaller incidents linked to a weakness in the way some Coldcard devices generated wallet seeds.
Galaxy said the higher figure would only be included if a suspected fourth wave of attacks is confirmed by affected wallet owners. At current prices, an additional 459 BTC would take the estimated total to about 2,055 BTC, worth close to $130m.
The research company published the updated figures on X on Monday. It said the fourth wave had been identified through blockchain analysis but was not yet supported by enough victim reports to be added to the confirmed total.
Galaxy believes the suspected activity was “substantially comprised of” one attacker. It has given that assessment medium-high confidence, although it warned that blockchain evidence alone cannot establish the identity of every victim or prove that all of the thefts were carried out by a single operator.
Alex Thorn, Galaxy’s head of firmwide research, first highlighted the possible fourth wave on 3 August after finding transaction patterns similar to those used in the earlier attacks. His estimate subsequently reached 448.7 BTC transferred from 709 potential victim addresses.
An earlier Galaxy analysis had identified about 1,815.75 BTC moving through four observed waves. However, the company said that number was based on on-chain activity rather than confirmed reports from wallet owners. The latest assessment therefore reduces the confirmed figure while retaining the larger estimate for the unverified fourth wave.
Galaxy said its investigators were continuing to map wallet addresses as more information became available from victims and others involved in the investigation.
The vulnerability affects seeds generated on Coldcard Mk3, Mk4, Mk5 and Coldcard Q devices running certain firmware versions.
Coinkite, the company behind Coldcard, said the problem was introduced in March 2021 during the integration of a new cryptographic library. The affected firmware did not use the intended hardware-backed true random number generator when creating wallet seeds. Instead, it mistakenly relied on a deterministic pseudo-random generator supplied by MicroPython.
Coinkite said its hardware random-number generator was still operating elsewhere in the firmware. That meant internal reviews were able to confirm the component was present without detecting that wallet creation had switched to a different source of randomness.
Block’s Bitcoin engineering and security team reached the same conclusion after conducting its own firmware review. Block said it had not completed full empirical testing on every affected device, but found that the vulnerable software used the deterministic MicroPython fallback rather than the STM32 hardware random-number generator during seed generation.
According to Coinkite, affected Mk2 and Mk3 devices may have supplied about 40 bits of effective entropy, while vulnerable Mk4, Mk5 and Coldcard Q devices may have generated roughly 72 bits instead of the intended 128 bits.
Galaxy said it was working with U.S. federal law enforcement agencies, cryptocurrency exchanges and cyber investigation groups. The firm has been sharing confirmed attacker and victim addresses as the investigation develops.
About 90% of the stolen Bitcoin remains untouched, according to Galaxy. None of the funds taken in the first three confirmed waves has moved since the thefts, giving investigators more time to monitor the addresses.
The company warned that other attackers could try to exploit the same weakness while vulnerable devices continue to be used. Identifying further attacker-controlled addresses would allow exchanges and authorities to react if the stolen coins begin moving.
Blockchain data showed that activity accelerated sharply during the suspected fourth wave, reaching about 13.8 wallet sweeps per Bitcoin block compared with approximately 0.3 sweeps per block before the incident. Most of the stolen balances were sent to newly created addresses rather than a single central wallet, while some later passed through second-hop transactions, making the funds more difficult to trace.
Galaxy previously said users who still controlled compromised wallets might have a limited chance to replace an unconfirmed theft transaction using Bitcoin’s Replace-by-Fee mechanism. That option is available only before miners confirm the original transaction and does not guarantee that funds will be recovered.
The firm said the attacks remained active and advised affected Coldcard users to move their funds to secure addresses and generate entirely new wallet seeds on patched devices.
Coinkite has released emergency firmware updates for all affected products: version 4.2.0 for Mk2 and Mk3, version 5.6.0 for Mk4 and Mk5, version 1.5.0Q for Coldcard Q, and Edge versions 6.6.0X and 6.6.0QX. The company has also destroyed remaining stock containing the vulnerable firmware.
Installing an update protects only wallets created after the fix. Seed phrases generated using vulnerable firmware remain exposed and should be replaced, Coinkite said.
The company recommends generating a new seed after updating the device, checking a receiving address, sending a small test transaction and moving the remaining balance only after the test has been completed successfully.
Coinkite added that wallets created using at least 50 fair private dice rolls are not exposed by this random-number-generation issue alone. A strong BIP-39 passphrase provides an additional layer of security, but the company still recommends migrating because the original vulnerable seed remains weak.
