XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Learn
● Learn

Coldcard Exploit Continues Draining Wallets as Theft Tally Reaches $88 Million

Galaxy Research tracks ongoing theft campaign targeting Coldcard hardware wallets, with losses now hitting approximately $88.6 million across 4,585 addresses after a third wave of attacks drained an additional 207.73 BTC.

JM
by Jacob Marquez · Learn Desk
Published August 2, 2026 · 2 min read

Theft Campaign Accelerates Against Compromised Coldcard Devices

An active theft campaign targeting Coldcard hardware wallets has now resulted in approximately $88.6 million in stolen Bitcoin, according to research firm Galaxy Research. The attackers have successfully emptied around 1,367 BTC across 4,585 separate addresses in three documented waves of thefts. Galaxy Research’s head of research Alex Thorn warned Saturday that the attack remains ongoing and urged all Coldcard users holding single-signature funds to move their Bitcoin immediately, describing the exploitation as deliberate, programmatic, and likely orchestrated using large language models.

March 2021 Firmware Error Left Private Keys Predictable

The vulnerability stems from a firmware flaw in Coldcard devices manufactured by Coinkite in March 2021. The faulty firmware generated seed phrases—the randomized strings that create private keys—with insufficient entropy, making the resulting private keys guessable to attackers. Thorn cautioned that every single-signature Coldcard address created after the March 2021 firmware update will eventually be drained, as the weakness in key generation cannot be remedied retroactively. Galaxy Research flagged approximately 600 suspected attacker addresses to federal investigators and compliance firms, with assistance from victims who shared transaction details to help map the on-chain theft patterns.

Years of Dormancy Before Attack Awakens

A striking aspect of the theft campaign: the compromised funds had sat untouched in victim wallets for an average of 3.18 years before being drained, indicating the breach remained undetected since the 2021 firmware error. The stolen Bitcoin currently remains parked in attacker-controlled addresses and has not been moved, preserving the transaction trail for investigators. The situation has triggered an unusual reversal in the crypto industry, with panicked users moving their Bitcoin away from self-custody addresses and onto centralized exchanges like Coinbase and Binance—an inversion of the traditional “not your keys, not your coins” ethos that normally drives toward self-custody adoption.

Source: Galaxy Research, via Decrypt. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Learn Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.