Galaxy Research Says Coldcard Hack Losses Have Exceeded $100 Million
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- Galaxy Research says confirmed Coldcard exploit losses exceeded $100 million across three attack waves and smaller incidents.
- Weak seed generation in Coldcard firmware may have allowed attackers to predict recovery phrases and steal Bitcoin.
- Metaplanet’s Simon Gerovich said the Bitcoin network remained secure because the exploit affected hardware, not the protocol.
Losses linked to the Coldcard hardware wallet exploit have passed $100 million, according to an August 4 update posted on X by Galaxy Research. The firm said it has high confidence that attackers stole 1,596 Bitcoin from about 7,300 addresses across three confirmed attack waves and 14 smaller incidents. The confirmed amount is now worth more than $100 million.
Galaxy Research added that the possible loss could rise to about 2,000 BTC, or nearly $130 million, if suspected but unconfirmed incidents are included. However, the company has not counted those cases as confirmed because some victims have not yet verified that their wallets were affected.
🚨LOSSES FROM COLDCARD HACK EXCEED $100M
High confidence 1,596 BTC has been stolen from ~7300 addresses across 3 confirmed waves + more 14 smaller incidents.
If we add suspected (but unconfirmed), the total balloons to $130m (2k BTC).
More in the thread below 👇 pic.twitter.com/RAl3ib67qa
— Galaxy Research (@glxyresearch) August 3, 2026
How the Coldcard Attack Unfolded Across Multiple Waves
The incident began on July 30, when engineers at Block first noticed a large group of Bitcoin addresses being drained. Galaxy Research later confirmed the first wave through reports from affected users. The opening attack moved 1,082.65 BTC from 1,196 addresses in only 41 minutes.
Galaxy then identified the second and third waves after receiving more victim reports. Most affected addresses appeared in only one wave, although researchers found some overlap. The firm also mapped several smaller incidents that occurred around the larger attacks.
A suspected fourth wave remains unconfirmed by any victim. Galaxy Research believes it may be connected to the same exploit, but it has kept those losses outside its high-confidence total. Blockchain activity can show where Bitcoin moved, but it cannot always prove why a transaction occurred or which wallet software created the address.
Weak Seed Generation Put Older Coldcard Wallets at Risk
The attack has been linked to weak randomness in some Coldcard firmware versions. A hardware wallet creates a recovery phrase, also called a seed phrase, that controls access to the Bitcoin connected to the wallet. If that phrase is generated with insufficient randomness, an attacker may be able to predict it and take the funds.
Coldcard maker Coinkite published a security advisory on July 30. The company said affected firmware produced seed phrases with less protection than expected. It released corrected firmware for the affected models but warned that installing an update does not repair an existing seed phrase.
Users with potentially affected wallets must first install the fixed firmware, create a completely new seed phrase, and move their Bitcoin to a new address. Coinkite advised users to test the new wallet with a small transaction before transferring the remaining balance.
Simon Gerovich Says the Bitcoin Network Was Not Compromised
Metaplanet CEO Simon Gerovich responded on August 3 and expressed sympathy for users who lost Bitcoin. He said the incident showed how difficult self-custody can be because individuals carry risks involving device flaws, lost keys, recovery and inheritance.
Gerovich said Metaplanet uses regulated institutional custodians, segregated cold storage, multi-party controls and independent oversight for its corporate Bitcoin treasury. He separated the wallet failure from Bitcoin itself, writing, “Nothing about this exploit was a failure of Bitcoin. The protocol was not compromised; a device was.” His comments focused on choosing a custody method that matches the level of responsibility and risk involved.
The Coldcard exploit is a painful week for many in our community, and I’m sorry for those who lost Bitcoin they believed was secure.
It is also a reminder that custody is one of the hardest problems in this industry. Self-custody asks individuals to carry every operational risk…
— Simon Gerovich (@gerovich) August 3, 2026
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







