The theft tied to a Coldcard hardware wallet flaw has grown to at least 1,367 Bitcoin (BTC), worth about $88.6mn, across three confirmed waves, with a fourth wave under way on 3 Aug that could push the total past $115mn.
As reported on 31 Jul, Coinkite, the Canadian maker of Coldcard, had disclosed a software bug that generated recovery phrases from weak randomness rather than the device's intended source, affecting wallets created on certain firmware versions across Mk3, Mk4, Mk5 and Q devices since 2021.
The scale has grown quickly since. Galaxy Research, which has tracked the exploit wave by wave, said a first sweep on 30 Jul drained 1,082.65 BTC from 1,196 addresses in 41 minutes. A second wave the same day added 76.16 BTC, and a third on 1 Aug added another 207.73 BTC, bringing the confirmed total to 1,367.05 BTC across 4,585 addresses.
Fourth wave still unresolved
A fourth wave began on 3 Aug and remains unresolved, with transactions still moving through the Bitcoin mempool. Galaxy Research head Alex Thorn said the pattern matched the UTXOs, the unspent transaction outputs, left behind on wallets generated by the flawed firmware. "These are likely Coldcard victims, they match the shape of Coldcard vulnerable UTXOs and the elevated transaction pattern gives me high confidence they are another wave of attacks," Thorn said in a post on X. He put the fourth wave at 388.93 BTC across 462 addresses, though later estimates from other trackers put the figure closer to 449 BTC and more than 700 addresses as confirmations continued.
If the fourth wave is confirmed in full, the cumulative loss would reach around 1,800 BTC, or about $115mn, across more than 5,200 addresses.
Remaining vulnerable inventory destroyed
Coinkite has said it destroyed its remaining vulnerable inventory and halted shipments. Founder and CEO Rodolfo Novak has acknowledged the company was unaware of the flaw until researchers identified it.
Galaxy Research has passed roughly 600 suspected attacker addresses to federal investigators and cybersecurity partners. None of the funds from the earliest waves had moved as of Saturday, which Galaxy said was unusual for a theft of this size and may indicate the attacker lacks a way to launder such a visible sum without drawing attention.