Summary
Galaxy Research raised its estimate of Bitcoin drained from addresses linked to the Coldcard firmware flaw to 1,367.05 BTC (~$88.6 million) across 4,585 addresses, identifying a third attack wave that removed an additional 207.7 BTC. The first wave drained 1,082.65 BTC from 1,196 addresses in just 41 minutes on July 30. Daily transfers below 1 BTC surged to 39,600 BTC — the highest since the FTX collapse in November 2022 — as users rushed to move funds.
Key Facts
- Total estimated losses: 1,367.05 BTC (~$88.6M) across 4,585 addresses
- First wave (July 30): 1,082.65 BTC from 1,196 addresses in 41 minutes (blocks 960,183-960,191)
- Second wave (July 31): 76.16 BTC from 1,478 addresses
- Third wave: 207.7 BTC from 1,912 addresses
- Sub-1 BTC daily transfers hit 39,600 BTC — highest since Nov 16, 2022 (39,900 BTC)
- Root cause: MicroPython software fallback supplied predictable output after March 2021 code change prevented hardware RNG from contributing properly
- Affected firmware: Mk2/Mk3 4.0.1-4.1.9; Mk4/Mk5 pre-5.6.0; Q pre-1.5.0Q
- Coinkite estimates ~40 bits of effective search space for Mk2/Mk3; ~72 bits for later models (vs intended 128 bits)
- Alex Thorn (Galaxy) warns attack is still ongoing — urges users to move funds immediately
Why It Matters
The Coldcard incident is the most significant hardware wallet security failure in Bitcoin's history, both in scale ($88.6M+) and in its structural implications for self-custody. The vulnerability persisted for over five years (March 2021 to July 2026) before discovery, affecting an unknown number of users. The surge in small Bitcoin transfers to levels not seen since FTX suggests widespread panic migration. The incident has reignited the self-custody vs ETF debate, with Bloomberg's Eric Balchunas arguing ETFs offer safer exposure, while Casa CEO Nick Neuman counters that self-custody's distributed nature gives users time to react.