Coldcard Bitcoin Theft Tops $100M and the Stolen Funds Still Haven't Moved
What Happened?
The Damage
Where the Money Is Now?
The Wallet Turned Graffiti Wall
What This Means for Self-Custody
Watch the Wallets

India Crypto Research
Over $100 million in Bitcoin has vanished from Coldcard wallets since 30th July. Nobody touched a single device to do it.
A firmware bug dating back to March 2021 caused some Coldcard Mk3 devices, running firmware versions 4.0.1 to 5.0.3, to generate wallet seeds using a predictable software process instead of the device's dedicated hardware randomiser. That let attackers reconstruct victims' private keys entirely offline. No phishing. No physical theft. Just a flaw in how the keys were made in the first place.
The theft hit in fast, brutal waves. On day one, 594 BTC (~$38M) disappeared in a 25-minute sweep. Then a revised count put the same opening window at 1,083 BTC (~$70M). By 3rd August, Galaxy Research had confirmed, with high confidence, 1,596 BTC taken from roughly 7,300 addresses across three waves plus 14 smaller incidents, totalling more than $100 million. Elliptic's chief scientist has since told reporters that a total closer to $130 million, once a suspected fourth wave is factored in, is roughly correct.
Researchers believe as many as a dozen different hackers may be exploiting the flaw independently. No single group has been identified. This wasn't one coordinated heist. It looks more like several attackers racing each other to the same vulnerable wallets.
Almost none of it has moved. Seven known attacker wallets were sitting on roughly $75M combined, untouched, in the days after the first waves, and Galaxy Research says around 90% of all stolen funds remain unmoved even now.
That's unusual for a hack this size. Researchers say it's likely because exchanges and blockchain monitoring firms are watching those wallets so closely that cashing out without getting caught has become very difficult. The money is stuck in plain sight.
One of those addresses, holding about $36 million, has become an unlikely public message board.
Using OP_RETURN, a Bitcoin feature that lets anyone attach a short, permanent text message to a transaction, people have been paying pennies to leave notes directly on the hacker's wallet. Some are desperate pleas: “please please please, return some.” Others are opportunistic: one message offers a 10% cut in exchange for help laundering the funds. And some are just strangers asking for donations while the wallet has the world's attention.
Whether the hacker is even reading any of it is unclear. The balance hasn't budged.
This has reignited the debate over self-custody. Bitcoin's whole promise is that you don't need to trust a bank or an exchange. But that promise only holds if the device generating your keys does its job correctly. One coding error, years old, was enough to undo it for thousands of people.
Coinkite has urged anyone who generated a seed on the affected firmware to move their funds immediately to a newly generated seed. A firmware update alone won't fix wallets that were already compromised. The damage was done the moment the seed was created.
The money hasn't moved yet. When it does, that's expected to be the first real clue to who's behind it.
India Crypto Research operates independently. The information presented herein is intended solely for educational and informational purposes and should not be construed as financial advice. Before making any financial decisions, it's essential to undertake your own thorough research and analysis. If you're uncertain about any financial matters, we strongly recommend seeking guidance from an impartial financial advisor.