Coldcard2026-08-18 16:02:53Coldcard hack probe points to possible FBI lead on first wave attackerLaw enforcement may already have a concrete lead on the operator behind the first and largest wave of the July 2026 Coldcard wallet drains, according to reporting by Bitcoin Magazine. The report centers on 1,082.65 BTC taken in the initial wave, a tranche that remains untouched in the attacker’s address and is still being watched on-chain. Alex Thorn of Galaxy Research said publicly that the identity of the Wave 1 attacker may be known to authorities, while Block engineering lead Clay Garrett said Block’s investigation traced the sweep pattern to a paid account at a major blockchain services provider whose internal logs matched the theft workflow with unusual precision. The article also reconstructs the vulnerability that made the theft possible: a bug introduced in March 2021 during Coldcard’s migration to libngu that redirected randomness generation away from the STM32 hardware RNG and into MicroPython’s Yasmarang PRNG fallback. According to the report, that reduced effective entropy to roughly 40 bits on older models and around 72 bits on newer ones. As of early August, confirmed and estimated losses across multiple waves had exceeded 1,800 BTC from more than 5,000 addresses, with roughly $118 million confirmed stolen. The piece reviews claims of a possible insider “retirement attack,” but says public evidence remains insufficient to support that conclusion.1740
Galaxy Resear2026-08-14 13:22:03Galaxy Research says more than 1,778 BTC stolen in Coldcard wallet exploit, with no new attacks confirmed after Aug. 6Galaxy Research said more than 1,778 BTC, worth about $112 million based on the figures cited in its post, has been stolen in attacks tied to a Coldcard hardware wallet vulnerability, and the final total is still expected to rise. According to the firm, attackers began systematically reconstructing mnemonic phrases generated by Coldcard and moving on-chain funds as early as the early hours of July 30. The research team said it has confirmed three main waves of attacks and more than 30 smaller traces, with trace E identified as the largest and most complex. Drawing on direct reports from more than 190 victims, Galaxy Research also identified at least 33 additional attacker traces. It said those traces cannot yet be confirmed as the work of a single attacker, but they do show that multiple attackers were active in the threat environment. As of now, no new attack activity has been confirmed after Aug. 6. Galaxy Research said that may be because vulnerable users have already moved funds or because most exposed funds have already been drained. The firm urged users of single-signature Coldcard wallets to move funds to fresh addresses as soon as possible.1390
Coldcard2026-08-04 09:41:39Fourth wave of Coldcard exploit linked to 462 suspected victims and 388.93 BTC in lossesOnchainLens said the Coldcard wallet exploit has now affected more than 5,200 addresses, with total stolen funds reaching about 1,816 BTC, worth roughly $114 million based on the figures cited in the report. The first three waves of attacks have been confirmed to account for 1,367.05 BTC in losses, or about $88.6 million. A fourth wave, identified through pattern matching, was tied to 462 suspected victims and losses of 388.93 BTC. OnchainLens said it is using on-chain data to identify the associated attacker cluster. The stolen funds have not yet been moved, but the cluster remains active, with its latest transaction recorded just minutes ago.1820
Coldcard2026-08-03 15:55:47Coldcard users recount losing life savings after wallet-seed flaw surfacedColdcard users are posting detailed accounts of drained wallets after a firmware flaw made some seeds generated by the hardware wallet guessable, according to TheDefiant. The report says attackers have swept about 1,816 BTC, valued in the article at roughly $114 million, from more than 5,200 addresses in four coordinated waves. Victims say they followed standard self-custody practices: buying from a well-known manufacturer, generating seeds offline, engraving backups into steel, and never entering seed phrases on internet-connected devices. Among the cases cited, Canadian entrepreneur Jonathan Goodman said 18.25 BTC was taken from wallets linked to a Coldcard that had never touched the internet and was stored in a safety deposit box. Other users described racing to recover seed backups while away from home, only to find their balances already at zero. On Reddit and X, posts from affected holders describe losses tied to retirement savings, family wealth plans, and years of bitcoin accumulation. Coldcard maker Coinkite has released patched firmware for all models, paused shipments, and destroyed remaining inventory carrying the affected firmware. CEO Rodolfo Novak, known as NVK, said the team was devastated and urged anyone who generated a seed on a Coldcard to move funds immediately. The open letter did not say whether users whose coins were already stolen would be compensated.1960
SecondFi2026-07-23 19:50:15SecondFi Sticks to Two-Week Recovery Plan After $2.4M Cardano Wallet ExploitSecondFi says its recovery plan remains on track after a Cardano wallet exploit drained 16 million ADA. Engineers are testing secure return methods, and a wallet checker tool is due next week.1900
LayerZero2026-07-15 08:24:53LayerZero executor wallet suspected in exploit with about $2.1 million in lossesSpecter said a LayerZero executor wallet appears to have been compromised in an incident spanning multiple blockchains, with total losses estimated at about $2.1 million. The stolen assets were then bridged to Ethereum through Stargate and Relay, according to the monitoring update. Specter added that the attacker currently holds 955 ETH, valued at about $1.78 million, along with 322,000 USDC. The firm also said CyversAlerts, a blockchain security organization, was the first to spot the unusual activity. The post did not provide additional technical details on how the wallet was compromised.1700