BrandLogo
Table of Contents

Coldcard Bitcoin Theft Tops $100M and the Stolen Funds Still Haven't Moved

What Happened?

The Damage

Where the Money Is Now?

The Wallet Turned Graffiti Wall

What This Means for Self-Custody

Watch the Wallets

intermediate

Coldcard Bitcoin Theft Tops $100M and the Stolen Funds Still Haven't Moved

By ICR Research Team|2 mins read
Last Updated on: Aug 11, 2026|Published On: Aug 11, 2026
Key Takeaways
  • $100M+ in BTC stolen from vulnerable Coldcard wallets.
  • The vulnerability dates back to 2021 and allowed private keys to be reconstructed without physical access.
  • Multiple attackers may be competing to drain the same vulnerable wallets.
  • ~90% of the stolen funds remain unmoved, making the attacker wallets highly visible and difficult to cash out.
  • One wallet holding around $36M has effectively become a public message board through Bitcoin’s OP_RETURN feature.
  • Updating firmware alone isn't enough for an already compromised wallet. Affected users need to generate a new seed and move their funds.
  • The next major development to watch is whether and when the stolen BTC starts moving.
India Crypto Research

Coldcard Bitcoin Theft Tops $100M and the Stolen Funds Still Haven't Moved

India Crypto Research

Over $100 million in Bitcoin has vanished from Coldcard wallets since 30th July. Nobody touched a single device to do it.

What Happened?

A firmware bug dating back to March 2021 caused some Coldcard Mk3 devices, running firmware versions 4.0.1 to 5.0.3, to generate wallet seeds using a predictable software process instead of the device's dedicated hardware randomiser. That let attackers reconstruct victims' private keys entirely offline. No phishing. No physical theft. Just a flaw in how the keys were made in the first place.

The Damage

The theft hit in fast, brutal waves. On day one, 594 BTC (~$38M) disappeared in a 25-minute sweep. Then a revised count put the same opening window at 1,083 BTC (~$70M). By 3rd August, Galaxy Research had confirmed, with high confidence, 1,596 BTC taken from roughly 7,300 addresses across three waves plus 14 smaller incidents, totalling more than $100 million. Elliptic's chief scientist has since told reporters that a total closer to $130 million, once a suspected fourth wave is factored in, is roughly correct.

Researchers believe as many as a dozen different hackers may be exploiting the flaw independently. No single group has been identified. This wasn't one coordinated heist. It looks more like several attackers racing each other to the same vulnerable wallets.

Where the Money Is Now?

Almost none of it has moved. Seven known attacker wallets were sitting on roughly $75M combined, untouched, in the days after the first waves, and Galaxy Research says around 90% of all stolen funds remain unmoved even now.

That's unusual for a hack this size. Researchers say it's likely because exchanges and blockchain monitoring firms are watching those wallets so closely that cashing out without getting caught has become very difficult. The money is stuck in plain sight.

The Wallet Turned Graffiti Wall

One of those addresses, holding about $36 million, has become an unlikely public message board.

Using OP_RETURN, a Bitcoin feature that lets anyone attach a short, permanent text message to a transaction, people have been paying pennies to leave notes directly on the hacker's wallet. Some are desperate pleas: “please please please, return some.” Others are opportunistic: one message offers a 10% cut in exchange for help laundering the funds. And some are just strangers asking for donations while the wallet has the world's attention.

Whether the hacker is even reading any of it is unclear. The balance hasn't budged.

Blog_Image

What This Means for Self-Custody

This has reignited the debate over self-custody. Bitcoin's whole promise is that you don't need to trust a bank or an exchange. But that promise only holds if the device generating your keys does its job correctly. One coding error, years old, was enough to undo it for thousands of people.

Coinkite has urged anyone who generated a seed on the affected firmware to move their funds immediately to a newly generated seed. A firmware update alone won't fix wallets that were already compromised. The damage was done the moment the seed was created.

Watch the Wallets

The money hasn't moved yet. When it does, that's expected to be the first real clue to who's behind it.

Disclaimer

India Crypto Research operates independently. The information presented herein is intended solely for educational and informational purposes and should not be construed as financial advice. Before making any financial decisions, it's essential to undertake your own thorough research and analysis. If you're uncertain about any financial matters, we strongly recommend seeking guidance from an impartial financial advisor.