The heist began in the early hours of July 30, 2026, but the strangest part isn't how aggressive the attack was — it's that once the thief got the money, they barely touched it. According to Galaxy Research's on-chain tracking, the Coldcard hardware wallet seed reconstruction attack has now confirmed over 1,778 BTC stolen, worth roughly $112 million. Yet as of block height 962,304 (data from August 13), 1,499.27 BTC — about $93.9 million — remains completely untouched, still sitting in addresses controlled by the attacker.
The root cause traces back to a 2021 firmware update. Coldcard's seed generation process was quietly switched from a hardware random number chip to a software-based alternative, dropping key strength from 128 bits all the way down to as low as 40 bits in some cases. Attackers didn't need phishing, didn't need to plant malware, and didn't even need physical access to the device — armed with just the device serial number and clock state, they could reverse-engineer the seed and sweep the coins on-chain.
Galaxy's breakdown of the attack's scale is remarkably precise: in the first few minutes of the attack, 1,082.65 BTC was drained from 1,195 addresses — worth about $70.5 million at the time. The largest single confirmed footprint, dubbed "Footprint E," took 209.94 BTC from 2,148 addresses, around $13.3 million. A third wave pulled 208.24 BTC from 1,912 addresses, about $13 million. Combined with 41 other smaller attack footprints, the incident has now affected more than 5,200 addresses in total.
But since August 6, none of the three major waves or any of the confirmed footprints have shown new attack activity. Galaxy's take is blunt: this doesn't mean the vulnerability has been patched — it more likely means high-risk users still relying on single-sig Coldcard wallets have already moved their funds, or that whatever could be stolen already has been. The research team has directly contacted more than 190 victims to verify losses and confirm new attack footprints, but continues to urge anyone still using a single-sig Coldcard wallet to move their funds to a brand-new address.
What's even more interesting is where the stolen funds have gone. Of the Bitcoin already stolen, only about 246 BTC has been moved by the attacker, and 65% of that flowed into Coinjoin mixing transactions. Galaxy could only trace the final destination of 174.97 BTC — most of which also went through Coinjoin, with only small amounts flowing to KuCoin and Jump Crypto. In other words, this haul is large enough — and hot enough — that even the attacker hasn't dared to cash out most of it yet.
Galaxy is still holding onto an unconfirmed fourth wave of footprints involving 638.5 BTC; if eventually counted, total losses would climb to 2,417 BTC, worth over $151.3 million at today's prices. The incident has also prompted roughly $15 billion worth of Bitcoin to be moved to safer custody solutions. Ledger has already issued a warning over the matter, arguing that wallet security mechanisms need to adapt to AI-assisted vulnerability discovery, while other hardware wallet makers have noted a wave of phishing attacks targeting users during the panic.






