Coldcard hack: how much has actually been stolen?

The Coldcard hack has drained an estimated 2,055 BTC, roughly $130 million, from vulnerable hardware wallets since the vulnerability went public on July 30, and the number is still climbing. Galaxy Research has formally confirmed 1,719 BTC (about $111 million) stolen across three attack waves, while a suspected fourth wave — first flagged Monday, August 3 — pushes the working total toward the $130 million figure that's now circulating widely. That gap between "confirmed" and "suspected" matters: analysts are still reconciling addresses, and the true figure will likely keep moving for another one to two weeks as victims self-report and Galaxy attributes more wallets to the exploit.

The root cause is a March 2021 firmware change that routed seed generation through a predictable software random-number generator instead of the device's dedicated hardware one. For any seed created in the roughly five years between that change and the July 30 disclosure, entropy — the randomness that makes a wallet's private key unguessable — was silently cut from a secure 128 bits to as little as 40 bits in the worst cases. A key that weak is brute-forceable with enough computing power, and once the flaw became public knowledge, at least 15 independent attackers began racing each other to drain exposed addresses before their owners could move funds.

Why a firmware update doesn't protect you

This is the part most coverage has glossed over: patching your Coldcard's firmware does nothing to fix a wallet that was already generated under the flawed process. The vulnerability lives in the seed itself — the 12 or 24 words that control your bitcoin — not in the software currently running on the device. Coinkite, the company behind Coldcard, has said as much in its own advisory: the only way to close the exposure is to generate a brand-new seed on updated firmware and move funds to it. Anyone who updates their device but keeps using an old seed is, functionally, exactly as exposed as they were before the patch shipped.

That mechanic explains why losses have kept accumulating for more than a week after the first fix went out. There's no deadline forcing action, no automatic protection, and no way for Coinkite to retroactively secure a seed it already handed out. The clock only stops for a given wallet when its owner personally migrates.

What changed with the Aug 3 RBF sweep wave

The fourth attack wave introduced a new wrinkle. Galaxy's Alex Thorn tracked roughly 448.7 BTC moved from around 709 addresses using replace-by-fee (RBF), a Bitcoin feature that lets a sender rebroadcast a pending transaction with a higher fee to jump the queue. Attackers are using it to push their sweeps through faster — but the same visibility cuts both ways. Because an RBF transaction sits in the mempool before it confirms, a victim who spots an attacker's sweep in progress can, in theory, outbid it with their own higher-fee transaction to their own wallet. It's the first wave where an affected holder has any real-time countermeasure at all, rather than simply losing a race that finished before they knew it started.

The scope of affected hardware has also widened since the initial disclosure. What began as a Mk3-specific issue now extends to Mk2, Mk4, Mk5 and the touchscreen Q model, per Coinkite's updated advisory — meaning the pool of potentially exposed users is larger than first assumed.

Do you need to move funds off your Coldcard now?

If your Coldcard generated its seed between March 2021 and the July 30 disclosure, and you haven't since migrated to a freshly generated seed on patched firmware, the honest answer is yes — treat it as exposed until proven otherwise. Updating firmware alone is not sufficient. The safer path is to generate a new seed on updated firmware, move your bitcoin to the new wallet, and retire the old one. Devices bought or initialized after the patch, or seeds you've already regenerated post-fix, aren't part of this exposure window.

There is a genuine upside for anyone still deciding what to do: Galaxy estimates roughly 90% of the stolen coins remain unmoved and traceable on-chain, which keeps some path to freezing or recovery open through exchanges and law enforcement, and it's a reminder that attackers, too, are working through a large backlog rather than instantly draining everything at once.

What happens next

This has already become the largest hardware-wallet exploit tracked in 2026, according to TRM Labs, and it lands inside a year that's seen more than 200 crypto hacks totaling roughly $950 million — feeding a broader narrative that self-custody carries operational risks retail investors often underestimate. That narrative pressure, not the dollar figure itself, is the more durable consequence here; $130 million is real money but small next to total Bitcoin market value, and Bitcoin's price — trading around $64,940 as of Friday, up roughly 2.8% over the past week — has already decoupled from the story entirely, moving instead on Fed rate-cut odds after a dovish jobs print.

The open question is how fast the remaining unmigrated seeds get swept versus how fast their owners move first. Expect Galaxy's confirmed total to keep grinding toward the $130 million suspected ceiling over the next couple of weeks, with new-wave risk shrinking but not disappearing as long as unpatched, unmigrated wallets remain out there. Coinkite's advisory could still expand further if more device batches turn out to be affected. None of that changes the one action item that actually matters for an individual holder: firmware updates fix new wallets, not old ones, and only a fresh seed closes the gap.

Sources