Recently, we covered the critical security failure in the Canadian hardware wallet COLDCARD. A flawed random-number algorithm generated predictable seeds, and attackers rebuilt the faulty generator to derive private keys and sweep matching wallets.
The damage has since widened considerably.
Three Waves, 4,585 Wallets, $88.6 Million
The on-chain analysis team Galaxy Research has been tracking Bitcoin transfers linked to the COLDCARD flaw. The cumulative haul now stands at 1,367 BTC, worth roughly $88.6 million at the time of transfer. Those funds came from 4,585 wallet addresses.
The attackers moved in three distinct waves.
The first struck on 30 July 2026. Within 41 minutes, the attacker drained 1,082.65 BTC from 1,195 addresses. This remains the largest single sweep so far.
The second followed on 31 July. It pulled 76.16 BTC from 1,478 wallets, a lower value per address but a wider reach.
The third ran from 31 July into 1 August. It touched 1,912 addresses and moved around 208 BTC. However, this wave differed in a telling way. Instead of funnelling funds into a few collection addresses, the attacker scattered them across 293 P2WSH addresses. Such addresses do not reveal their script conditions until the funds are spent, which makes it far harder for outside observers to confirm whether a single actor controls them.
Researchers caution that on-chain data alone cannot yet prove the third wave came from the same attacker. Others may have identified the same pool of vulnerable addresses and followed with their own sweeps.
Exchanges See a Surge in Bitcoin Deposits
While researchers tracked stolen coins, centralised exchanges also registered a sharp rise in Bitcoin inflows. On 31 July, net inflows across centralised exchanges hit 11,163 BTC. Platforms such as River, Binance, Kraken, and OKX all saw noticeably higher deposit volumes.
That does not mean the attacker sent all of those coins, though. A thief may well avoid centralised exchanges for fear of having funds frozen. The attacker would more likely launder the Bitcoin through decentralised channels.
Many of the exchange deposits probably came from other COLDCARD owners instead. After learning about the breach, those users may have rushed to move their balances onto centralised platforms to keep them safe.
A Hard Lesson for Hardware Wallets
The irony stings. Many experienced users choose hardware wallets precisely for stronger security. A hardware wallet gives the owner sole control, while centralised exchanges and custodial wallets carry the risk of the platform mishandling or losing funds.
Yet this incident exposes a flaw in that logic. Security depends entirely on the wallet manufacturer. If the firmware or algorithm carries a defect, user funds become vulnerable. To make matters worse, COLDCARD cannot intervene against the attacker remotely, because these wallets have no over-the-air update mechanism.
All the company can do now is urge customers through every available channel to transfer their funds and update firmware immediately. Unfortunately, a large number of users remain unaware of the breach. As time passes, the count of compromised wallets will only keep growing.
One clarification deserves emphasis. This incident reveals the risks of a specific manufacturing defect. It does not mean that all hardware wallets are inherently unsafe.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.