Coldcard Bitcoin losses rise to $88.6M in third wave
Galaxy Research raised its estimate of Bitcoin drained from addresses linked to the Coldcard firmware flaw to 1,367.05 BTC, worth about $88.6 million, on Aug. 1.
- 1,367.05 BTC was drained across 4,585 addresses in three suspected Coldcard attack waves, Galaxy reported.
- July 30’s first wave removed 1,082.65 BTC from 1,196 addresses in just 41 minutes total.
- Firmware updates fix new seed generation but cannot repair vulnerable seeds created on earlier releases.
The research unit identified 4,585 affected addresses across three suspected attack waves, replacing its earlier estimate of 1,082.65 BTC from 1,196 addresses.
The revised figure means the $70.2 million estimate reported after Galaxy’s first analysis is no longer current. Galaxy described the total as its “estimated observed size,” leaving open the possibility that further transactions could be found. The company has not proved that every address came from a vulnerable Coldcard seed.
Galaxy raises Coldcard estimate after third wave
Galaxy’s first mapped wave occurred between 1:10:20 a.m. and 1:51:26 a.m. UTC on July 30. It traced 1,082.65 BTC from 1,196 addresses across blocks 960,183 through 960,191. The transactions appeared about 30 hours before Coinkite issued its initial public advisory.
A second wave on July 31 drained 76.16 BTC from another 1,478 addresses. Galaxy later identified a third wave that removed 207.7294 BTC from 1,912 addresses. Together, the three groups brought the observed total to 1,367.05 BTC across 4,585 addresses.
The first wave used the same 30 satoshis per virtual byte fee and transactions without change outputs. Those traits helped researchers identify the related movements onchain. Galaxy warned that later attacks might use different patterns, making the complete loss harder to measure.
Three waves used different transaction patterns
Galaxy said the first two waves shared collector addresses, destination types and derivation-path behavior. The events also occurred about 27 hours apart. Those similarities suggested one operator may have conducted both sweeps, although the blockchain cannot establish the attacker’s identity.
The third wave behaved differently. Funds from each victim moved to separate pay-to-witness-script-hash destinations, while several victims were grouped into each sweep transaction. The activity also checked only the default derivation path. Galaxy said it was confident each wave represented one operator, but would not claim that one attacker controlled all three.
Therefore, descriptions of a single hacker remain an inference rather than a confirmed fact. Galaxy called the third group “what we suspect are hacks of Coldcard-generated addresses.” The wording reflects the limits of onchain attribution.
Coinkite said a series of firmware integration errors prevented the intended hardware random-number generator from contributing properly to seed creation. A MicroPython software fallback supplied predictable output after a March 2021 code change. Block’s independent technical report described the same random-number-generator path and said active exploitation was underway.
Coinkite estimated about 40 bits of effective search space for affected Mk2 and Mk3 seeds. Later Mk4, Q and Mk5 models included extra secure-element entropy, but the company estimated roughly 72 bits rather than the intended 128 bits. These figures remain technical estimates and may change as testing continues.
The affected Mk2 and Mk3 range covers firmware 4.0.1 through 4.1.9. Seeds created on Mk4 and Mk5 before standard version 5.6.0, and Q seeds created before version 1.5.0Q, are also affected. Separate fixed Edge releases are available.
Existing seeds require migration, not only updates
Coinkite released hotfixes for every affected model and said it takes “full accountability” for the bug. However, installing new firmware only corrects future seed generation. It cannot add entropy to a recovery phrase that already exists.
The official Coldcard advisory tells users to install the fixed firmware, generate a completely new seed, verify its backup and receiving address, and send a small test transaction before moving the remaining balance. Users should keep the previous backup until the migration is confirmed.
Coinkite said seeds created with at least 50 fair, independent and private dice rolls are not considered exposed by this issue alone. A strong, unique BIP-39 passphrase adds another barrier, but the company still advises migration. Short, reused or predictable passphrases may not provide adequate protection.
However, the 594.48 BTC sweep identified by AnchorWatch’s Rob Hamilton. In related coverage, a later technical review examined how the firmware build error weakened Coldcard seeds for more than five years.
Coinkite’s investigation remains open, and the company has promised a formal technical review. Galaxy may also revise the observed loss again if new address patterns emerge. Until those reviews are complete, $88.6 million is the latest public estimate, not a final confirmed total. No verified Bitcoin price reaction has been attributed to the Coldcard incident so far.