Go Back

Coldcard Wallet Hack May Reach $130M as Fourth Attack Wave Emerges

Coldcard Wallet Hack May Reach $130M as Fourth Attack Wave Emerges

Murugaverl Mahasenan

Murugaverl Mahasenan

Make Catenaa preferred on (opens in a new tab)

Catenaa, Tuesday, August 04, 2026- Losses linked to the Coldcard hardware wallet vulnerability could rise to about 2,055 Bitcoin, valued at approximately $130 million, as investigators continue tracking a suspected fourth wave of coordinated thefts, according to Galaxy Research.

The research firm said it has already identified 1,596 BTC stolen from around 7,300 wallet addresses across three confirmed attack waves and an additional 14 smaller security incidents. If a fourth suspected wave is confirmed, total losses would increase to about 2,055 BTC.

The attacks exploit a vulnerability affecting recovery seeds generated on several versions of Coinkite’s Coldcard hardware wallets, including the Mk3, Mk4, Mk5 and Coldcard Q devices. Following disclosure of the issue, Coinkite released emergency firmware updates for all affected products and said it had destroyed remaining vulnerable inventory.

Reports of the exploit first surfaced on July 30, with investigators describing the thefts as highly automated and suggesting artificial intelligence tools may have assisted attackers in identifying vulnerable wallets at scale.

Galaxy Research said it has medium-to-high confidence that the suspected fourth wave is largely linked to a single attacker, although additional victim confirmations are still required before it can be formally classified.

The firm said it is working with U.S. federal law enforcement agencies, cryptocurrency exchanges and cyber investigation teams, supplying confirmed attacker and victim wallet addresses to assist ongoing investigations.

According to Galaxy, about 90% of the stolen Bitcoin has not yet been moved, while all assets stolen during the first three confirmed attack waves remain dormant on-chain, raising hopes that exchanges and authorities could potentially identify or freeze assets if they are transferred.

Galaxy warned that the attacks remain active and urged Coldcard users to immediately move their Bitcoin to secure addresses generated using newly created recovery seeds on patched devices or other trusted hardware wallets.

The incident is emerging as one of the largest hardware wallet security breaches affecting Bitcoin self-custody users in recent years and highlights the continuing importance of secure seed generation and firmware verification for long-term digital asset storage.