BrandLogo
Table of Contents

What Went Wrong Inside the Wallet

Galaxy Research's Numbers, Verified and Growing

How the Thefts Were Actually Carried Out

What This Means for Bitcoin Self-Custody Holders

intermediate

How a Five-Year-Old Coldcard Bug Drained Over $115 Million in Bitcoin

By India Crypto Research|6 mins read
Last Updated on: Aug 19, 2026|Published On: Aug 19, 2026
Key Takeaways
  • Root cause. A five-year-old firmware bug, not a device hack. A March 17, 2021 update quietly rerouted seed generation from Coldcard's hardware random number generator to a predictable software fallback. Entropy collapsed from 128 bits down to as low as 40. Attackers never needed physical access to a wallet.
  • Rising loss figures reflect better tracing, not new theft. Losses climbed with each Galaxy Research update. $88.6M on August 1. $115M confirmed by August 16. Most of that jump is Galaxy tracing more addresses back to the same March 2021 flaw. Attack activity itself stopped appearing after August 6.
  • Most stolen Bitcoin hasn't moved. Of the roughly 1,778 BTC identified, about 1,531 BTC sits untouched in attacker-controlled addresses. That's 86%. It leaves a real window for law enforcement and exchange coordination before any large cash-out.
  • Updating the firmware doesn't fix an already compromised wallet. Anyone who generated a seed on vulnerable Coldcard firmware between March 2021 and the August 2026 patch needs to move funds to a freshly generated seed. The patch only protects new seeds going forward.
  • Attribution is now a live thread, not just a loss story. An August 17 investigation suggests Wave 1's transaction pattern may carry identifying clues about the attacker. Galaxy's August 16 victim interviews strengthened the direct link between every confirmed loss and the March 2021 seed flaw.
India Crypto Research
LearnPart of a series
Coldcard Hack
Current Article
How a Five-Year-Old Coldcard Bug Drained Over $115 Million in Bitcoin
  • 1. What Went Wrong Inside the Wallet
  • 2. Galaxy Research's Numbers, Verified and Growing
  • 3. How the Thefts Were Actually Carried Out
  • 4. What This Means for Bitcoin Self-Custody Holders

A single firmware commit made on March 17, 2021, has cost Bitcoin holders more than $115 million as of August 16, 2026. Galaxy Research, the blockchain intelligence arm of Galaxy Digital, has spent 18 days tracing the theft back to that one release, speaking directly with over 200 victims to reconstruct exactly how attackers found and emptied their wallets. The vulnerability sat in plain, publicly viewable code for more than five years before anyone appears to have exploited it. What Galaxy's investigation shows is not just the scale of the loss, but a forensic map of how the theft actually unfolded, address by address, wave by wave.

What Went Wrong Inside the Wallet

Coldcard is a hardware wallet: a small physical device made by the Canadian company Coinkite that generates and stores the private keys that control a Bitcoin holder's coins. It is kept deliberately offline so it cannot be hacked remotely. The entire security promise of a hardware wallet rests on one step: generating a truly random "seed," the master string of words that all of a wallet's private keys are derived from. Randomness here is not a nice-to-have. If an attacker can predict or narrow down the possible seeds a device could have produced, they can reconstruct the private keys without ever touching the device.

That is what happened. A firmware update released on March 17, 2021, when Bitcoin was at block height 674,951, quietly rerouted Coldcard's seed generation away from its dedicated hardware random number generator, a chip built specifically to produce unpredictable output, and onto a software fallback: a predictable pseudorandom number generator running on the general-purpose chip. In practical terms, this collapsed the effective randomness of affected seeds from 128 bits down to as little as 40 bits. Each bit doubles the number of possible seeds an attacker must search through, so this was not a modest weakening. It took a search space that would be uncrackable and shrank it to one a well-resourced attacker could feasibly recreate offline.

The bug went undetected in a wallet marketed as one of the most security-focused in the Bitcoin ecosystem. Attackers only began exploiting it in earnest starting July 30, 2026, meaning vulnerable seeds sat exposed, unexploited, for more than five years before someone acted on the flaw.

Blog_Image


Galaxy Research's Numbers, Verified and Growing

Galaxy Research's public dataset lists 8,680 addresses connected to the theft, together holding roughly 1,778.6 BTC. That is the scope Galaxy can trace on-chain. A narrower, higher confidence figure comes from direct victim contact: 192 people have come forward with confirmed losses, covering about 1,790 addresses and 714.8 BTC between them.

The total value of the theft has moved with both new tracing and Bitcoin's price. Early estimates on August 1 put losses at 1,367.05 BTC, about $88.6 million, across 4,585 addresses. By August 4, Galaxy had identified 1,596 BTC stolen from 7,300 addresses across three confirmed attack waves, warning that a fourth, unconfirmed wave could push the total toward 2,000 BTC. As of August 16, the date of Galaxy's most recent public update, confirmed losses stand at roughly $115 million, and Galaxy has said the true figure could climb past $150 million once currently unmoved funds and unconfirmed clusters are fully accounted for.

Most of the affected seeds were generated in 2021 and 2022, the period immediately following the flawed firmware release, when Coldcard adoption among self-custody holders was climbing. That timing matters for anyone trying to assess whether they are exposed. A wallet seed generated on vulnerable firmware in that window carries risk regardless of how carefully the device itself was otherwise used.

Blog_Image

How the Thefts Were Actually Carried Out

Galaxy's investigation didn't stop at totalling the losses. It built a forensic fingerprint of the attackers' behavior, using patterns in block timing, transaction fees, lock times, and destination addresses to group the thefts into distinct waves and footprints.

PatternScaleBehavior
Wave 1About 1,082.65 BTC (blocks 960,183 to 960,191)One victim's coins per transaction, swept into four collection addresses
Wave 219 victimsDistinct transaction habits from Wave 1 and Wave 3
Wave 363 victimsDistinct transaction habits from Wave 1 and Wave 2
Footprint EUp to 795 victims in a single transaction (median 118 per transaction)Batches many victims' coins together rather than sweeping one at a time

Source: Galaxy Research. Data as of August 16, 2026.

The table above illustrates why Galaxy is confident these are the work of multiple distinct operators, or at least multiple distinct operating patterns, rather than a single actor working uniformly. Wave 1's method, one victim per transaction into a small set of four collection addresses, is mechanically very different from Footprint E's approach of batching hundreds of victims into one transaction. Some attackers scattered stolen funds across hundreds of addresses to complicate tracing. Others kept everything concentrated in just a handful of wallets.

Galaxy's newer data, published August 14, adds a further layer. Of the roughly 1,778 BTC identified as stolen, the large majority, about 1,531 BTC, remains sitting unmoved in attacker-controlled addresses. Of the smaller portion that has moved, roughly 65% has flowed through CoinJoin transactions, a privacy technique that mixes multiple users' transactions to obscure which coins belong to whom, making the funds harder to trace to a final destination such as an exchange. Attack activity across Galaxy's confirmed waves and footprints stopped appearing after August 6, which Galaxy attributes to the pool of easily reachable vulnerable wallets running dry rather than the underlying method failing.

August 18 Update: The Forensic Picture Gets Sharper

No large new theft or laundering transfer was confirmed on August 18. The meaningful development instead is that the forensic trail connecting the theft to its root cause, and possibly to the attacker, got noticeably stronger.

Galaxy Research's conversations with over 200 victims on August 16 reinforced a detail that was already suspected: the affected coins trace back to wallets created around March 17, 2021, the same date the vulnerable firmware shipped. In practical terms, this closes off the possibility that some of the losses came from an unrelated cause. Every dollar in the confirmed dataset now ties directly back to the seed generation flaw, not a separate phishing or malware vector.

The second development sits on the law enforcement side. A separate investigation published August 17 argues that the transaction pattern behind Wave 1, the fastest and largest sweep, may carry identifying clues about the operator behind it. This is forensic intelligence rather than a confirmed identification. In other words, investigators may already hold information useful for attribution, but no name or entity has been publicly confirmed as responsible.

Three specific on-chain positions were also being tracked as of August 18, based on publicly available blockchain data:

Tracked itemStatus as of August 18
Address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r562.02021083 BTC held across 11 unspent outputs, no pending transactions, last indexed activity August 1
64.9 BTC Wasabi transfer64.90373764 BTC moved into a Wasabi-related address on August 5, 2026, at 04:42:48 UTC; no confirmed onward destination identified
30.185 BTC transferMoved to a new wallet on August 7, as reported by Lookonchain; no confirmed subsequent mixer or exchange deposit identified

Source: on-chain tracking data, Galaxy Research. Data as of August 18, 2026.

Taken together, these three positions reinforce the broader pattern already visible in Galaxy's wave and footprint data: attackers are largely holding, not cashing out. The bottom line for August 18 is not a bigger number. It is a stronger case linking every confirmed loss to the March 2021 flaw, and an early but real possibility that Wave 1's operator could eventually be identified.

What This Means for Bitcoin Self-Custody Holders

The Coldcard incident is a reminder that hardware wallets shift where risk lives, not whether it exists. A device can be air-gapped, open source, and marketed as best in class, and still fail at the one step, seed generation, that everything else depends on.

  • Updating firmware does not fix an already generated seed. If a seed was created on vulnerable firmware between March 2021 and the August 2026 patch, the fix only prevents new seeds from being weak. Funds already tied to an old, compromised seed need to be moved to a freshly generated wallet.
  • Seeds generated with independent entropy sources were not affected. Seeds created using at least 50 independent dice rolls, or protected with a strong BIP-39 passphrase (an additional word added on top of the standard seed phrase), fall outside this specific flaw.
  • Galaxy's investigation is ongoing, and attribution is now a live thread. The gap between the 8,680 address public dataset and the 192 directly confirmed victims suggests the final tally, and the final dollar figure, is still moving. Galaxy has flagged $150 million as a plausible ceiling rather than a final number, and separate investigators are now examining whether Wave 1's transaction pattern can help identify the attacker.
  • Unmoved funds remain the larger story. With roughly 1,531 BTC still sitting in attacker-controlled addresses rather than cashed out, the window for law enforcement and exchange coordination to intercept further movement has not closed.

Bitcoin holders using any hardware wallet, not Coldcard specifically, should treat seed provenance as a question worth revisiting periodically, not a one-time setup detail.

Disclaimer

India Crypto Research operates independently. The information presented herein is intended solely for educational and informational purposes and should not be construed as financial advice. Before making any financial decisions, it's essential to undertake your own thorough research and analysis. If you're uncertain about any financial matters, we strongly recommend seeking guidance from an impartial financial advisor.