Galaxy Research says more than 1,778 BTC stolen in Coldcard wallet exploit, with no new attacks confirmed after Aug. 6

Galaxy Research says more than 1,778 BTC stolen in Coldcard wallet exploit, with no new attacks confirmed after Aug. 6

N
News Editor
2026-08-14 13:22:03
Galaxy Research said more than 1,778 BTC, worth about $112 million based on the figures cited in its post, has been stolen in attacks tied to a Coldcard hardware wallet vulnerability, and the final total is still expected to rise. According to the firm, attackers began systematically reconstructing mnemonic phrases generated by Coldcard and moving on-chain funds as early as the early hours of July 30. The research team said it has confirmed three main waves of attacks and more than 30 smaller traces, with trace E identified as the largest and most complex. Drawing on direct reports from more than 190 victims, Galaxy Research also identified at least 33 additional attacker traces. It said those traces cannot yet be confirmed as the work of a single attacker, but they do show that multiple attackers were active in the threat environment. As of now, no new attack activity has been confirmed after Aug. 6. Galaxy Research said that may be because vulnerable users have already moved funds or because most exposed funds have already been drained. The firm urged users of single-signature Coldcard wallets to move funds to fresh addresses as soon as possible.
Galaxy ResearchColdcardBitcoinwallet exploiton-chain trackingsecurity incidentpolicy and regulation

Galaxy Research said in a post on X that more than 1,778 BTC has been stolen through a Coldcard hardware wallet vulnerability, a figure it valued at about $112 million. The firm added that the final loss total is still expected to increase.

According to Galaxy Research, attackers had been systematically reconstructing mnemonic phrases generated by Coldcard and transferring on-chain funds since at least the early hours of July 30. The firm said it has confirmed and tracked three main waves of attacks, along with more than 30 smaller attack traces. Among them, trace E was described as the largest in scale and the most complex in execution.

Using direct reports from more than 190 victims, Galaxy Research said it also identified at least 33 additional attacker traces. It said it could not yet determine whether those traces were linked to the same attacker, but it had confirmed that multiple attackers were present in the broader threat environment.

As of now, Galaxy Research said it has not confirmed any new attack activity after Aug. 6. The firm said that may be because vulnerable users have already moved their funds, or because most of the exposed funds have already been drained. It still advised users with single-signature Coldcard wallets to move funds to fresh addresses as soon as possible.

Of the stolen funds, 1,531 BTC remains parked at addresses controlled by the attackers and has not moved, while about 246 BTC has already been transferred. Galaxy Research said 65% of that moved amount flowed into CoinJoin transactions, while 35% continued moving on-chain through carefully constructed peel chains and other methods. Only a very small portion could be partially traced to deposits at exchanges or cross-chain bridges.

Galaxy Research said it has shared a list of attacker addresses with crypto exchanges, compliance investigation firms and law enforcement agencies, with the aim of freezing those addresses if they reach centralized platforms. The firm added that it will continue taking reports from victims and providing tracing assistance.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.