Galaxy Research latest on-chain monitoring shows that a firmware vulnerability attack on the Coldcard cold wallet has already resulted in the theft of 1,366.3865 BTC, worth about $86.6 million. (Backgrounder: Coldcard MK3 cold wallet “seed vulnerability” — 594 bitcoins were swept in 25 minutes; the official urged users to move their assets as soon as possible.) (Additional context: Galaxy Research — the Coldcard vulnerability led to 1,082 BTC stolen, with losses exceeding $70 million.) Because the Bitcoin holders whose Coldcard cold wallets were targeted by the firmware vulnerability are still suffering escalating losses, the situation is getting worse. According to Galaxy Research’s latest on-chain monitoring report this morning, the attackers currently control 1,367.05 BTC, with affected addresses reaching 4,585; the total stolen amount has risen to about $86.6 million. JUST IN: A third Coldcard hack has been reported with another 207.7294 BTC stolen. A total of 1,367.05 BTC has been stolen from 4,585 addresses so far, according to Galaxy Research. Users are urged to review the company's official security guidance as soon as possible pic.twitter.com/MOAxi200xV — Bitcoin Magazine (@BitcoinMagazine) August 1, 2026. What’s even more notable is that Galaxy Research points out that the third-wave attack differs clearly from the first two waves in several behavioral characteristics: abandoning shared aggregation addresses, switching to P2WSH scripts, and, on average, emptying the wallets of 6.37 victims per batch. The organization admits that on-chain data cannot determine whether this is the result of the same attacker adjusting their tools, or whether another independent attacker targeted the same batch of already-exposed vulnerable key material and took the opportunity to “get a piece of the pie.” Three waves, very different on-chain fingerprints The first and second waves show highly similar patterns: funds were aggregated into at least several shared addresses, using the same combination of P2WPKH output formats and derivation paths. The time gap between the two waves was only 27 hours, leading to a reasonable inference that the same attacker was behind them. Differences are limited to the fee settings, and whether RBF (Replace-By-Fee, i.e., fee acceleration via replacement) signaling was enabled. The third wave completely changes the playbook. Rather than concentrating funds into a small number of aggregation addresses, the attacker assigns an independent destination address for each victim. The way funds are stored also changes—from P2WPKH to P2WSH multisignature scripts. The “sweep” schedule also shifts. In the first and second waves, victims’ wallets were emptied one by one. In the third wave, however, funds from an average of 6.37 victims were packaged and transferred out together, significantly improving efficiency. In addition, the third wave scans only the default derivation paths, with a narrower scanning range than in the first two waves. 40 bits of entropy set the stage for a five-year unexploded bomb Looking across a longer timeline, the root cause of this vulnerability traces back to March 2021, when a serious error appeared in the Coldcard Mk3 firmware integration: the seed generation process was mistakenly guided toward a deterministic software pseudo-random number generator rather than the originally designed STM32 hardware random number generator. Coinkite, the official hardware manufacturer, confirmed that the affected Mk3 seed entropy was only about 40 bits—far below the 128 bits that should normally be present—effectively reducing the “password strength” of the vault door to a level that is nearly brute-force crackable. This “unexploded bomb” was not officially triggered until July 30, 2026. Most victim wallets held less than 1 BTC, but the overall stolen total was still largely contributed by a small number of high-value wallets. The victim profiles closely resemble those of typical personal self-custody users. The official currently advises that all Coldcard Mk3 users who have ever run firmware versions 4.0.1 or higher should assume that any existing seed has already been leaked. They should move their assets to a brand-new hardware-generated wallet as soon as possible, rather than merely updating the firmware. The incident has also reignited discussion in the market about confidence in Bitcoin self-custody. Some analysts believe that concerns about the hardware wallet supply chain and firmware quality may actually encourage more investors to shift toward third-party custodial Bitcoin ETFs rather than holding the private keys themselves. Related report: CZ comments on cold wallet theft of $70 million — “Nothing is 100% safe!” Ledger and Trezor hardware wallets publicly broken via “antenna device” — Ledger: method is impractical, nearly impossible. SlowMist | Solana public chain large-scale coin theft incident forensic analysis report (continued)"Coldcard cold wallet theft amount rises to $86.6 million: 4,585 affected addresses, 1,367 BTC drained" This article was first published on BlockTempo (Movers & Shakers — the most influential blockchain news media), Dongqu BlockTempo.
