Coldcard attack is still active as stolen funds reach 1,367.05 BTC, Alex Thorn warns

Coldcard attack is still active as stolen funds reach 1,367.05 BTC, Alex Thorn warns

N
News Editor
2026-08-02 03:36:04
Coldcard users are being urged to move funds immediately after the amount tied to the ongoing wallet attack climbed to 1,367.05 BTC, worth about $88.6 million, across 4,585 addresses. Alex Thorn, head of research at Galaxy, said the attack is still unfolding and warned that any assets still sitting in affected Coldcard-generated addresses remain at risk. He said three previously identified large-scale attack waves showed similar transaction patterns and appeared programmatic, with signs of automation. Most of the stolen bitcoin from those waves has not yet moved and remains in attacker-controlled addresses. Thorn also said smaller opportunistic attackers have recently emerged, moving and laundering funds within hours, with some of the stolen assets passing through cross-chain services including ThorChain and ending up at offshore gambling platforms. According to Thorn, all Coldcard single-signature addresses generated after a firmware upgrade in March 2021 could ultimately be vulnerable. He added that the stolen funds had been dormant for an average of 3.18 years, with a median of 3.55 years, suggesting long-term holders were among the main victims.

Coldcard’s ongoing compromise has now been linked to 1,367.05 BTC in stolen funds, worth about $88.6 million, spanning 4,585 addresses, according to a BlockBeats report published on Aug. 2.

Alex Thorn, head of research at Galaxy, said the attack is still underway and warned users who have not yet moved funds to transfer assets out of affected Coldcard-generated addresses immediately. He also asked impacted users to come forward with information that could help trace the stolen funds and support reports to law enforcement.

Three major attack waves showed similar patterns

Thorn said three previously confirmed large-scale attack waves shared clear programmatic characteristics. Their transaction patterns were similar, and the activity may have been automated. The bitcoin stolen in those cases is still sitting in attacker-controlled addresses and has not been moved.

At the same time, he said smaller opportunistic attackers have started to appear. Those actors have been moving and laundering funds within hours, with some of the stolen assets flowing through cross-chain services such as ThorChain and then reaching offshore gambling platforms.

Risk tied to single-signature addresses created after March 2021 firmware update

According to Thorn, all Coldcard single-signature addresses generated after the March 2021 firmware upgrade could ultimately be drained, and users should complete fund migration as soon as possible.

The stolen funds had previously been dormant for an average of 3.18 years, with a median dormancy period of 3.55 years. Thorn said the victims were mainly long-term holders.

Addresses have been shared with U.S. law enforcement

Thorn said most of the stolen assets identified so far still have not moved. He added that the relevant addresses have already been submitted to U.S. law enforcement agencies and industry contacts.

In his view, the incident is a major blow to Bitcoin self-custody and shows the need for better security practices, stronger user education, and clearer warnings about the complexity of self-custody.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
11500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.