Logo Daily Crypto Briefs
Open menu

Coldcard Losses Top $100M as Confirmed Theft Tally Reaches 1,596 Bitcoin

5 min read
Breaking News
Large official red COLDCARD wordmark above a greyscale hardware wallet, blank transaction-evidence strips and unbranded warning markers on an off-white and charcoal editorial background.

TL;DR

  • Galaxy Research said it had high confidence that 1,596 Bitcoin had been stolen from roughly 7,300 addresses across three confirmed Coldcard attack waves and 14 smaller incidents, as of its August 4 public update.
  • The confirmed amount was worth more than $100 million near Bitcoin's August 5 price, while a separately classified suspected fourth wave could raise the running estimate to about 2,055 BTC, or roughly $130 million.
  • The new tally is a material escalation from Coldcard's July 31 seed-warning coverage: it adds a confirmed on-chain loss total, address count and attack-wave breakdown to the previously reported active-exploitation warning.
  • Coinkite says updating firmware does not repair a seed made on affected software; holders must create a new safe seed and migrate funds.

TORONTO, August 5, 2026

Galaxy Research said it had high confidence that 1,596 Bitcoin had been stolen from roughly 7,300 addresses tied to the Coldcard seed-generation flaw, a confirmed toll worth more than $100 million near Bitcoin’s August 5 price and a material escalation from the July 31 vulnerability warning.

The August 4 public update separated that number from a suspected fourth attack wave, which could lift the running estimate to about 2,055 BTC, or roughly $130 million, but was not counted in the high-confidence total. The distinction is important: the incident remains active, and observed on-chain patterns are not the same thing as a final victim-verified loss count.

Bitcoin traded near $64,000 on August 5 after moving between roughly $59,500 and $66,500 over the preceding month, according to Kraken’s Bitcoin price page. The Crypto Fear and Greed Index was 27, or Fear, while the theft estimate was revised higher.

The figures are from Galaxy Research’s public update, which said the 1,596 BTC total covered three confirmed mass waves plus 14 smaller incidents. Coinkite’s security advisory remains clear on the immediate action: a firmware upgrade protects future seed creation but cannot repair a seed made on affected software.

Bitcoin

BTC
July 6 to August 5, 2026
$64,210
+2.6%
Jul 6 - Aug 5 | High $66,521 Low $62,594

Confirmed Coldcard losses pass 1,500 Bitcoin

The update puts a concrete on-chain impact measurement behind the security alert. Galaxy said its confirmed estimate covered about 7,300 addresses, three mass sweeps and 14 smaller incidents, rather than every address that may have been exposed by the defective seed-generation path.

At about $64,000 per Bitcoin, 1,596 BTC equates to roughly $102 million. The dollar figure is therefore a price-time estimate, not a separate amount recovered or reported by each victim, and will move with BTC even if the token count does not.

That is a sharp change from the Coldcard RNG flaw report, published July 31, which documented Coinkite’s migration warning and Block’s statement that exploitation was under way. What was newly known by August 4 was the scale of thefts observed to date, the address count and the division between confirmed mass activity and smaller related incidents.

Independent researchers at Block Engineering said affected firmware could use a deterministic software random-number fallback instead of the intended hardware source. That reduced the uncertainty protecting a seed phrase, allowing attackers who could reproduce the relevant conditions to search for wallet keys without taking physical possession of the device.

The failure is distinct from a phishing or malware event, such as the fake-app threat discussed in our Ledger and Trezor wallet-security coverage. Here, the concern is whether the recovery seed itself was created with enough independent randomness, not whether a user later disclosed it.

Coldcard’s fourth attack wave remains separate

Galaxy did not add the suspected fourth wave to its 1,596 BTC high-confidence count. The research team said including it could raise the working total to about 2,055 BTC, but it classified the activity separately because its grouping rested on on-chain pattern analysis rather than confirmed victim reports.

Early observations of that suspected wave identified roughly 389 BTC moving through 218 transactions from 462 addresses during a narrow block range on August 3. Later estimates were higher, which is another reason the article uses the confirmed total as its headline figure and treats $130 million as a conditional estimate, not a settled loss total.

The report also described 14 smaller footprints beyond the three confirmed waves. That points to a threat that may no longer be limited to one coordinated operator, but the chain data cannot by itself prove the identity or number of attackers. Neither Galaxy nor Coinkite has publicly attributed the thefts to a named group.

The evidence gives users a clearer urgency signal than the initial advisory did. A wallet that has not been swept is not thereby shown to be safe, and a falling average size in one wave would not establish that the searchable key space has been exhausted.

What changed after the July 31 Coldcard warning

Coinkite’s original remedy has not changed. Users with a seed generated on affected firmware should create and verify a new seed on fixed firmware or an unaffected device, send a small test transaction and then migrate the remaining balance. An update cannot add entropy to a seed already made.

The company’s advisory covers Mk3 seeds created on firmware 4.0.1 or later and certain pre-fix Mk4, Mk5 and Q seeds. Coinkite said users who supplied sufficient private dice entropy during seed creation are in a different position, but those who used fewer than 50 rolls or are unsure of their setup should follow the migration guidance.

For holders, the immediate practical risk is operational as well as cryptographic. Re-entering an old seed into a phone, website or unfamiliar desktop application during a rushed migration can create a separate route to loss. The safer process is to establish the replacement wallet first and independently verify its receive address before sending funds.

Fear & Greed Index

August 5, 2026
27 Fear

The next evidence to watch is whether Galaxy moves the fourth wave into its confirmed figure, whether new victim reports alter the address or BTC counts, and whether stolen funds begin to move from the tracked destinations. The confirmed position as of Galaxy’s August 4 update is narrower but significant: 1,596 BTC from about 7,300 addresses, with the potential fourth-wave estimate explicitly separate.

Stay up to date

Get the latest crypto insights delivered to your inbox

Fact-checked by: Daily Crypto Briefs Fact-Check Desk

Frequently Asked Questions

How much Bitcoin was stolen in the Coldcard hack?

Galaxy Research said on August 4, 2026 that it had high confidence 1,596 BTC had been stolen from roughly 7,300 addresses across three confirmed waves and 14 smaller incidents. At Bitcoin's price near $64,000 on August 5, that confirmed amount exceeded $100 million.

Does the Coldcard fourth attack wave count in the 1,596 BTC total?

No. Galaxy kept the suspected fourth wave separate from its high-confidence 1,596 BTC tally because it was identified through on-chain pattern analysis rather than confirmed victim reports. Including the suspected wave would raise the running estimate to about 2,055 BTC.

What is new since Coldcard's July 31 RNG vulnerability warning?

The July 31 coverage established that affected seeds were at risk and that exploitation was under way. The August 4 update added a specific confirmed theft total, an affected-address count, three confirmed mass waves and 14 smaller incidents, with another suspected wave under review.

Does a Coldcard firmware update protect an already affected seed phrase?

No. Coinkite says the update improves future seed generation but does not repair a seed created on affected firmware. The company directs affected users to create a new secure seed and migrate funds after verifying the replacement wallet.