- Galaxy Research tracks 1,596 BTC stolen from Coldcard wallets.
- Suspected fourth wave could raise losses toward $130 million.
- Affected users urged to migrate funds to secure wallets.
The Coldcard hack investigation has expanded after Galaxy Research estimated potential losses could reach 2,000 BTC, worth about $130 million. The research firm confirmed 1,596 BTC stolen from 7,300 addresses across three attack waves and 14 smaller incidents. A suspected fourth wave could increase the total if victims confirm that their wallets are affected.
Coldcard Hack Investigation Tracks Multiple Attack Waves
Galaxy Research stated that the Coldcard hack remains active as investigators analyse blockchain activity linked to the wallet vulnerability. The firm identified confirmed thefts from affected addresses while working with exchanges, law enforcement agencies, and cybersecurity groups.
The research firm said it has medium-high confidence that the suspected fourth attack wave involves a similar attacker pattern. However, Galaxy noted that it still requires direct victim confirmation before including those losses in the official count.
The vulnerability affected seeds created on certain Coldcard firmware versions. Coinkite previously confirmed issues involving Mk3, Mk4, Mk5, and Coldcard Q devices. The company released emergency firmware updates and advised users to migrate funds.
Bitcoin Losses Linked To Coldcard Wallet Vulnerability
The Coldcard hack resulted from a seed-generation issue that weakened wallet randomness. Coinkite said affected firmware versions used a deterministic generator instead of the intended hardware-based random source during seed creation.
Galaxy reported that around 90% of stolen Bitcoin remains unmoved. None of the BTC from the first three confirmed attack waves has moved, allowing investigators more time to monitor related addresses.
Meanwhile, Coinkite recommended users create new seeds on updated devices and transfer funds carefully. The company warned that updating firmware alone does not protect wallets created with vulnerable seeds.
Affected users should generate replacement wallets, verify receiving addresses, and complete small test transactions before moving remaining balances. The company also destroyed vulnerable inventory and released patched firmware versions across supported devices.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. CoinCryptoNewz is not responsible for any losses incurred. Readers should do their own research before making financial decisions.




