Logo Daily Crypto Briefs
Open menu

Coldcard Losses Reach $116M as TRM Counts Fourth Attack Wave

6 min read
Breaking News
Large official red COLDCARD wordmark on a dark plaque beside a greyscale hardware wallet and unbranded transaction evidence slips on red, charcoal and off-white editorial panels.

TL;DR

  • TRM Labs said it traced roughly 1,816 BTC from more than 5,200 addresses across four waves tied to the Coldcard seed-generation vulnerability, valuing the theft at about $116 million on Aug. 5.
  • The new assessment brings a fourth wave into a single on-chain estimate, while the prior Galaxy Research tally kept a suspected fourth wave separate from its 1,596 BTC high-confidence total.
  • TRM said the stolen Bitcoin had shown limited laundering at the time of its review and did not attribute the activity to a specific actor.
  • Coldcard maker Coinkite says a firmware update cannot repair a vulnerable seed already created; affected holders should create a new seed and migrate funds.

TORONTO, Aug. 18, 2026

TRM Labs said it traced roughly 1,816 Bitcoin from more than 5,200 addresses in four waves tied to the Coldcard seed-generation vulnerability, valuing the observed theft at about $116 million in an Aug. 5 assessment that brought a previously separate fourth wave into a single on-chain estimate.

The new count does not replace every earlier figure. Galaxy Research’s Aug. 4 assessment put its high-confidence total at 1,596 BTC across three confirmed mass waves and 14 smaller incidents, while keeping a suspected fourth wave separate. TRM used a different review date and methodology, so the two address counts and totals should not be added together.

The technical issue remains urgent for people who created a wallet seed on affected Coldcard firmware. Coinkite says updated firmware can improve future seed generation but cannot add entropy to an old seed, meaning a holder who may be exposed needs a new seed and a careful migration rather than an in-place update.

Bitcoin traded near $64,700 on Aug. 18, compared with roughly $65,200 on July 19, according to Kraken’s Bitcoin market page. The roughly 1,816 BTC in TRM’s assessment was therefore worth about $117 million at that later reference price, though the security firm’s $116 million figure reflects its Aug. 5 snapshot.

Bitcoin

BTC
July 19 to Aug. 18, 2026
$64,669
-0.8%
Jul 19 - Aug 18 | High $65,216 Low $62,819

TRM Counts 1,816 Bitcoin Across Four Coldcard Waves

In its on-chain investigation, TRM said the drains began July 30 and involved more than 5,200 addresses over four waves. The firm described the fourth wave as still moving through the mempool at the time of its assessment, so its figure is a measured snapshot rather than a final accounting of every affected wallet.

The distinction is important in a security incident with several tracking methods. The earlier Coldcard theft update reported Galaxy’s narrower confirmed figure and its separate provisional fourth-wave estimate. TRM’s report provides a useful follow-up because it counts four waves together and describes an observed amount that is larger than Galaxy’s three-wave high-confidence tally.

Neither figure proves a completed victim registry. A Bitcoin address can be traced on-chain, but seed provenance, the number of people behind those addresses and the relationship among attack waves require more evidence. TRM said transaction patterns could indicate multiple attackers and did not attribute the thefts to a named group.

At the time of its review, TRM said most stolen Bitcoin had pooled at a limited number of attacker-controlled addresses, with only limited laundering observed. It cited a 64.9 BTC Wasabi deposit and 200 Ether sent to Tornado Cash on Aug. 4. Those movements are evidence of activity, not proof that the perpetrators have cashed out the full balance.

Coldcard Seed Flaw Turned Wallet Keys Into a Search Problem

The incident centers on wallet seeds, not a failure of the Bitcoin blockchain. Block Engineering’s analysis found that affected firmware could fall back to predictable software-generated values where strong random input was expected, reducing the difficulty of reconstructing some keys.

TRM said the weakness began with firmware version 4.0.1 in March 2021 and could cut seed strength as low as 40 bits under affected conditions. That is a security property, not an investment outcome: reducing entropy gives an attacker a much smaller set of possible seeds to search without stealing a device or persuading a user to disclose a recovery phrase.

Coldcard’s own Mk3 seed-generation warning says that updating firmware does not fix a seed already generated by affected software. The manufacturer’s mitigation is to create a new secure seed and move funds, a process that needs care because importing the old recovery phrase into a website or untrusted app would create an additional theft risk.

The case differs from the malware route described in our earlier Ledger and Trezor wallet-security report. Here, the central question is whether the seed was created with adequate randomness, even if the device stayed offline and the owner never typed the phrase into a phishing page.

Fourth-Wave Evidence Keeps the Migration Clock Running

For potentially affected holders, the material change is not only the dollar figure. A fourth wave in a later on-chain assessment means a wallet that remained untouched after the first reports cannot be presumed safe. A device update may stop the same weakness from affecting new seeds, but it does not make a preexisting weak seed unpredictable.

The practical process is to identify whether the wallet was created on an affected model and firmware path, establish a new seed on fixed firmware or an unaffected device, verify the replacement receive address independently and move funds. Coinkite’s advisory includes model and firmware guidance; holders who are uncertain should use that primary guidance rather than a social-media checklist.

The losses also show why theft totals must be described with an as-of date and attribution. Galaxy’s 1,596 BTC and TRM’s 1,816 BTC are not competing claims that can be casually combined. They are separately reported, time-bound attempts to measure a fast-moving set of on-chain transactions, with differing treatment of the fourth wave and address scope.

The Crypto Fear and Greed Index read 41, or Fear, on Aug. 18. It is not a measure of the Coldcard incident, but it places the continued attention to self-custody risk in a cautious broader market setting.

Fear & Greed Index

Aug. 18, 2026
41 Fear

The next evidence to watch is whether new sweeps appear from the same vulnerable seed space, whether on-chain analytics firms reconcile their fourth-wave classifications and whether the traced holdings move into services that can freeze or identify them. For now, the strongest supported update is TRM’s Aug. 5 snapshot: about 1,816 BTC from more than 5,200 addresses across four waves, not a final victim-verified loss ledger.

Stay up to date

Get the latest crypto insights delivered to your inbox

Fact-checked by: Daily Crypto Briefs Fact-Check Desk

Frequently Asked Questions

How much Bitcoin did TRM Labs trace in the Coldcard attack?

TRM Labs said it traced about 1,816 BTC from more than 5,200 addresses across four waves as of its August 5, 2026 assessment. It valued that amount at about $116 million at the time. The figure is an on-chain estimate and may differ from other firms' methodology or victim-verified totals.

What changed in the Coldcard fourth-wave update?

The earlier Galaxy Research update counted 1,596 BTC across three confirmed mass waves and kept a suspected fourth wave separate. TRM's later assessment included four waves in one estimate, describing a total of roughly 1,816 BTC from more than 5,200 addresses.

Can a Coldcard firmware update protect an affected seed phrase?

No. Coinkite says updated firmware helps future seed generation but cannot repair a seed made with affected software. Holders who may be affected should create a new secure seed and migrate funds after independently verifying the new wallet.

Has the Coldcard attacker been identified?

No public attribution was made in TRM Labs' assessment. TRM said transaction patterns could indicate multiple attackers and that the available on-chain evidence did not establish a specific actor.