Attackers slowed but the damage keeps growing: Galaxy Research says the Coldcard seed-extraction exploit has so far drained at least 1,778 BTC — roughly $112 million — and the final toll could swell well past $150 million. What happened - The exploit dates to the morning of July 30, 2026, when attackers began systematically recreating Coldcard-generated seeds and sweeping victims’ BTC onchain, Galaxy Research reports. The firm says it has “very high confidence” in its tally, based on confirmed, owner-attributed thefts and direct conversations with more than 190 victims. - The root cause traces to a 2021 Coldcard firmware change that moved seed generation off the device’s hardware random-number generator and into a software substitute. That decision slashed entropy from about 128 bits down to as little as 40, enabling attackers to reconstruct seeds from a device’s serial number and clock state — without phishing, malware, or physical access. Scale and activity - Galaxy’s tracked losses include one massive opening wave and dozens of smaller strikes. The largest confirmed wave (Wave 1) grabbed 1,082.65 BTC from 1,195 addresses in the first minutes — roughly $70.5 million at the time. - Other notable confirmed clusters: Footprint E took 209.94 BTC across many addresses (about $13.3M), and Wave 3 swept 208.24 BTC (around $13.0M). Across three proven waves and 41 smaller footprints, Galaxy maps more than 5,200 drained addresses. - As of block 962,304 (data through Aug. 13), attackers still control about 1,499.27 BTC (nearly $93.9M) that remains unmoved. Of the ~1,778 BTC stolen, roughly 1,531 BTC is unmoved and about 246 BTC has been moved post-theft; roughly 65% of the moved coins have flowed into CoinJoin privacy rounds. - Galaxy hasn’t observed confirmed attacker activity after Aug. 6. That may reflect fewer vulnerable targets remaining, not a failure of the attack method. - The firm is also tracking a candidate fourth wave of 638.5 BTC that remains unconfirmed; if validated it would raise the total to about 2,417 BTC (roughly $151.3M). Where the coins went - Of the smaller portion that reached final endpoints (about 174.97 BTC), most entered CoinJoin rounds. Small amounts reached centralized services including KuCoin and Jump Crypto. Wider fallout and guidance - The exploit has accelerated a shift of roughly $15 billion in Bitcoin into “safer custody” as holders react. Ledger warned that wallet security needs to evolve to counter AI-assisted discovery of vulnerabilities, and other hardware-wallet makers have flagged an uptick in phishing attempts exploiting user panic. - Galaxy’s advice is direct: if you still hold funds on a single-signature Coldcard wallet, move them to new addresses immediately. Bottom line The immediate wave of thefts appears to have slowed, but a substantial portion of stolen BTC remains in attacker-controlled addresses and the total losses could still climb if additional footprints are confirmed. Coldcard users and custodians should assume vulnerability until a clear remediation path is confirmed and take defensive action now. Read more AI-generated news on: undefined/news