Newsroom
4 August, 2026 / News / AI / Tags: firmware, waves, seeds, galaxy, addresses

Confirmed thefts reach 1,596 Bitcoin across three waves, with a suspected fourth pushing potential totals higher while most funds remain unmoved
Galaxy Research has revised its assessment of Bitcoin stolen through a long-standing Coldcard hardware wallet vulnerability, placing confirmed losses at 1,596 BTC from roughly 7,300 addresses across three major attack waves and 14 smaller incidents. If a suspected fourth wave is fully verified, the total could climb to about 2,055 BTC, valued at nearly $130 million at recent prices.
The research firm stressed that the higher figure remains provisional because it has not yet obtained sufficient confirmation from affected wallet owners for the latest cluster of transactions. Investigators continue refining address mapping as more reports arrive.
The underlying flaw originated in a March 2021 firmware change. While integrating a new cryptographic library, seed generation on affected devices switched from the intended hardware-backed true random number generator to a deterministic pseudo-random function supplied by MicroPython. The hardware generator continued operating elsewhere in the code, so internal checks did not immediately flag the problem.
As a result, seeds created on vulnerable firmware possessed far less entropy than designed. Coinkite estimates that Mk2 and Mk3 devices delivered roughly 40 bits of effective randomness, while Mk4, Mk5 and Coldcard Q models produced about 72 bits instead of the intended 128. Attackers could generate candidate seeds offline, derive corresponding addresses and match them against the public blockchain without ever touching a physical device.
The vulnerability affects seeds generated on specific firmware ranges: Mk2 and Mk3 versions 4.0.1 through 4.1.9, Mk4 and Mk5 before 5.6.0 (or Edge before 6.6.0X),and Coldcard Q before 1.5.0Q (or Edge before 6.6.0QX). Devices such as TAPSIGNER, OPENDIME and SATSCARD are unaffected because they use different codebases. The critical factor is the firmware present when the seed was first created, not the version currently installed.
The first large-scale sweep occurred on July 30, when approximately 1,082.65 BTC left 1,196 addresses in about 41 minutes. Subsequent waves followed. By early August, on-chain tracking showed roughly 1,367 BTC moved from 4,585 addresses. Galaxy’s latest confirmed tally incorporates additional smaller incidents and raises the figure to 1,596 BTC.
Alex Thorn, Galaxy’s head of firmwide research, identified a fourth coordinated pattern on August 3. Transaction activity between certain blocks moved hundreds of Bitcoin—estimates ranging from roughly 389 BTC to an adjusted 448.7 BTC after filtering non-matching addresses—from several hundred potential victim wallets. Sweeps ran at rates far above baseline levels observed before the incident. Some funds already advanced to second-hop addresses, complicating tracing.
Galaxy noted that each of the first three waves appeared internally consistent with a single operator’s methods, though researchers have not established that one actor controlled every incident. Once the vulnerability became public knowledge, additional parties may have begun scanning for and draining exposed wallets.
Coinkite has released emergency firmware updates for every affected product line and destroyed remaining inventory that contained vulnerable code. Installing the patched firmware protects only wallets created afterward. Existing seeds generated under the flawed versions stay compromised and must be replaced.
The company advises users to install the fixed firmware, generate an entirely new seed, verify a receiving address, send a small test transaction and only then transfer the remaining balance. Seeds created with at least 50 fair, private dice rolls are not considered exposed by this specific entropy issue. A strong BIP-39 passphrase adds a further barrier, yet Coinkite still recommends full migration.
Galaxy investigators have shared confirmed attacker and victim addresses with U.S. federal law enforcement agencies, cryptocurrency exchanges and cyber investigation groups. The firm continues to map additional attacker-controlled addresses so that exchanges and authorities can respond quickly if the funds begin to move.
In some cases where transactions remain unconfirmed and signal Replace-by-Fee support, users who still control the original wallet may attempt to broadcast a higher-fee replacement. Success is not guaranteed and depends on timing before miners include the original transaction.
The public warning triggered a sharp rise in transfers of small Bitcoin balances. One analysis recorded 39,600 BTC moved in amounts under 1 BTC in a single day—the highest such volume since the period immediately after the FTX collapse in late 2022. While not every transfer originated from a Coldcard user, the timing aligned closely with the security advisory.
Security researcher Jameson Lopp observed that the episode illustrates practical limits of the “don’t trust, verify” principle for most individual users. Average owners cannot personally audit every layer of firmware, hardware and software in a self-custody setup and therefore rely on manufacturers, developers and independent researchers. The incident does not invalidate self-custody, he argued, but underscores the value of avoiding single points of failure.
Confirmed loss figures may continue to change as additional victims report addresses and as analysts evaluate the suspected fourth wave. For users whose seeds may have been generated on vulnerable firmware, the priority remains generating a new seed on patched hardware and moving funds promptly.









