Galaxy Research identified 3 suspected attacks targeting vulnerable Coldcard-generated Bitcoin addresses, resulting in the theft of 1,367 BTC worth about $88.6 million.
Galaxy Research has identified 3 suspected attack waves that targeted Bitcoin addresses generated by vulnerable Coldcard wallets. The firm’s on-chain investigation revealed that 1,367.05 BTC valued at approximately $88.6 million was drained from 4,585 addresses. The research also suggested that the attacks are still ongoing. So, those who may have affected wallets should transfer their money as soon as possible to minimize additional risks.
Galaxy Research Identifies Three Large-Scale Coldcard Bitcoin Wallet Attacks
Galaxy Research used only Bitcoin blockchain data to come up with its findings. The company said it has not determined if all impacted addresses were generated with inadequate randomness. But the transaction pattern is pretty clear that it’s a coordinated attack on a known vulnerability in some Coldcard wallets.
The Coldcard exploit is ONGOING. Move Coldcard single-sig funds to safe locations immediately!
We have reported ~600 addresses we believe to be hackers holding funds stolen from Coldcard-generated weak entropy addresses to federal investigators, industry compliance firms, and…
— Galaxy Research (@glxyresearch) August 2, 2026
Those who have not moved their Bitcoins out of the affected wallets should move them as soon as possible, according to Galaxy Research Head of Research Alex Thorn. He also pointed out that the stolen Bitcoins have not been transferred to any other address yet and are still inside of attacker-controlled addresses.
Read more: Ekubo Hack Drains $1M in WBTC as Users Urged to Revoke Approvals – Ledger Tribune
The report showed that the stolen coins had remained untouched for years before the attacks. The Bitcoin’s average holding period was 3.18 years, with the median period being 3.55 years. This pattern suggests that the majority of victims were not active traders but rather long-term Bitcoin investors.
The first attack wave was detected by Galaxy Research on July 30, 2026. In just 41 minutes, attackers drained 1,196 high value addresses and 1,082.65 BTC. Each transaction had a fixed fee of 30 sat/vB, and no change outputs. These identical transaction patterns suggested the use of automated software.
The second attack occurred on July 31, 2026, about 27 hours after the first wave. The attackers stole another 76.16 BTC from 1478 smaller wallets. Galaxy Research discovered that this wave was very similar to the first attack in terms of structure and derivation paths. For this reason, researchers have surmised that both attacks were likely the work of the same attacker, but have not been confirmed.
Coldcard Vulnerability Leaves Some Bitcoin Wallets at Risk
The third attack occurred from 31st July to 1st August 2026. This attack was not as successful as the previous one, as it only managed to gain access to 1,912 addresses and steal 208.24 BTC. This wave sent money to different P2WSH addresses rather than money collection wallets. It also only considered the default derivation path. That makes this attack either a new version of the original attack or a new attacker taking advantage of the same vulnerability, Galaxy Research says.
Galaxy Research identified the potential flaw as a software fallback problem with the Coldcard seed generation process. Some of the affected devices reportedly replaced the device’s built-in STM32 hardware true random number generator (RNG) with a software pseudorandom number generator. That software relied on predictable information such as non-secret chip data and internal timers.
The available randomness was reduced, so that an attacker could allegedly repeat the key generation process without using the internet. They then compared those keys to active bitcoin addresses on the blockchain to find wallets that had money.
Coldcard Wallet Attacks Affect Mk3 Devices, Galaxy Research Urges Immediate Action
The reported problem is primarily affecting Coldcard Mk3 devices with March 2021 firmware v4.0.1 or newer, which created master seed phrases. Wallets that are manually rolled or imported from trusted external hardware, however, are deemed to be safe. In general, the Coldcard Mk4, Mk5, and Coldcard Q devices are not vulnerable to this particular software fallback bug with their normal hardware generation process.
Furthermore, Galaxy Research cautioned that just upgrading the firmware was not enough to secure any Bitcoin already connected to a vulnerable seed phrase. Instead, affected users should immediately transfer funds to a temporary secure wallet or trusted exchange before installing the latest emergency firmware updates.
Users should then completely wipe the device and create a new 12-word or 24-word recovery phrase using the patched firmware. Galaxy Research also suggested adding additional randomness when creating seeds by using manual dice rolls. Last but not least, users should move their Bitcoins into new secure addresses. These measures can help to remove the exposure to the infected key space and minimize the likelihood of future theft.

Bilal Hassan is a seasoned crypto journalist with over five years of experience covering blockchain, digital assets, and global fintech trends. His work focuses on market developments, regulatory shifts, and the evolving landscape of cryptocurrency adoption worldwide.

