News linked to both this project and an event.
according to Bitcoin News monitoring, analysis by Galaxy Research (@glxyresearch) has identified distinct characteristics among various groups that exploited weakly secured COLDCARD seeds in their attacks. The 10 largest groups alone transferred approximately 1,700 BTC, with the biggest group moving over 1,080 BTC. Researchers differentiated the attackers based on patterns such as fee strategies, transaction timing, fund consolidation methods, and the destinations of the stolen BTC. Several of the largest groups are still suspected to hold nearly all of the stolen BTC. Victims of COLDCARD attacks can contact @intangiblecoins to assist in gathering evidence and reaching out to relevant authorities.
Odaily News, Galaxy Research Head Alex Thorn stated on the X platform that attacks exploiting the Coldcard hardware wallet vulnerability have noticeably declined, but cumulative losses continue to rise as more victims come forward. The impact of this incident on the Bitcoin community is significant, as the victims are primarily long-term BTC holders who adhered to self-custody cold storage principles, rather than those who lost assets due to high-risk trading or DeFi activities.At a scale of $112 million, this incident ranks among the top 20 largest hacks in crypto history and is one of the most severe security breaches in the hardware wallet self-custody sector to date. Bitcoin culture may be entering a new phase—the era of relying solely on ideological advocacy and extreme self-custody promotion is coming to an end. The community needs to place greater emphasis on technical security, lower the barrier to entry for users, and avoid simply shifting the burden of security responsibility onto ordinary users. This crisis may ultimately drive the Bitcoin ecosystem to establish a more mature security framework.Galaxy Research has directly contacted 190 victims and has confirmed with high confidence that the exploit has led to the theft of 1,778.84 BTC (approximately $112.7 million) from over 8,600 addresses. This tally does not yet include certain moderately credible suspicious attack records, such as the unconfirmed "Wave 4." If these potential attack scopes are incorporated, total losses could expand to 2,417.35 BTC (approximately $153 million).Meanwhile, the incident is reshaping market perceptions of self-custody security. Galaxy noted that multisig wallets have emerged as the "winners" of this event, with no stolen transactions traced to multisig wallets so far. Multisig service providers including Casa, Unchained, Nunchuk, and Anchorwatch have all observed a notable increase in user registrations and BTC inflows.
Odaily News: According to monitoring by Galaxy's Head of Research, since July 31, they have communicated with over 190 victims of the Coldcard vulnerability attack, and have asked victims who have not yet been in touch to reach out via direct message so they can provide tracking information and assist in reporting losses to relevant authorities. Since August 6, no new attacks have been confirmed, but this does not mean that new attacks cannot occur, and vigilance should be maintained.
Odaily News: Hardware wallet Coldcard has suffered a hack, with no confirmed total loss amount yet. Blockchain analytics platform CryptoQuant has confirmed losses of 1,432 BTC, while Galaxy Research places a high-confidence minimum estimate at 1,730 BTC. Other analyses suggest the scale of losses could be even higher. Research firm Galaxy Research stated that its earlier estimate of 1,816 BTC represents a potential figure, not a confirmed total. As of Tuesday, the firm's confirmed high-confidence minimum loss stands at 1,730 BTC, with over 450 BTC directly confirmed based on victim reports. Blockchain intelligence firm TRM Labs estimates that the attacker moved approximately 1,816 BTC from more than 5,200 addresses in four phases. CryptoQuant stated that its confirmed figures only include addresses publicly disclosed by victims and verified through on-chain patterns, meaning the tally could rise as more victims come forward with information. (Cointelegraph)
Odaily News – According to monitoring by Galaxy's Head of Research, the median dormancy period for stolen coins is 3.5 years, with 88% of stolen coins being over one year old. By address, the median loss is 0.014 BTC and the average loss is 0.212 BTC; over 250 victim reports have been received. Based on victim reports, the median loss is 1.022 BTC and the average loss is 4.04 BTC, with reported losses ranging from 624 satoshis to 58.97 BTC.
Odaily News: DefiLlama data shows that hackers stole $247 million in crypto assets in July, making it the second-highest month since 2026, trailing only April's $644 million; this figure represents a significant increase from June's $75 million and May's $60 million. Galaxy Digital stated that the Coldcard vulnerability was the largest attack event of the month, confirming three rounds of attacks involving 7,300 wallets, with at least $100 million in Bitcoin stolen; the firm also identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million. DefiLlama's hack tracker estimates losses related to this vulnerability at $115 million. Other attacks in July include a $9 million exploit on decentralized finance protocol Bonzo Lend, a $2.6 million theft from Cardano-based wallet SecondFi, a $24 million theft from Arbitrum-based perpetual trading platform AFX, and a $7.5 million theft from the Verus Ethereum Bridge.
Odaily News: According to Bitcoin News monitoring, Galaxy Research stated that the largest known COLDCARD theft incident involves 1,159 BTC, distributed across seven attacker addresses, which remain untouched to date, with 0 BTC cashed out or transferred through mixers. The relevant BTC was stolen within 41 minutes, but approximately 600 attacker addresses have been flagged by law enforcement agencies, exchanges, and blockchain analysis firms. Meanwhile, a smaller-scale attacker appears to have begun cleaning funds. On-chain analysts have tracked 64 BTC entering mixers, of which only about 10 BTC initially completed mixing, 54 BTC returned as change, and were subsequently split into outputs of approximately 7 BTC each for further mixing. Analysts noted that these unusually large outputs remain easy to trace, making this cleaning attempt relatively transparent.
Odaily News: According to Bitcoin News monitoring, Alex Thorn of Galaxy Research stated that researchers initially identified the first wave of COLDCARD thefts through a distinctive on-chain pattern: thousands of automated asset transfer transactions used the same fixed fee rate and exhibited identical transaction behavior. This characteristic enabled analysts to trace attacker activity across Bitcoin UTXO history and map out multiple rounds of coordinated theft.
Odaily News, Chainalysis posted on X platform stating that the Coldcard hack has been particularly devastating for Bitcoin holders in Canada. Our analysis of the attackers and victims found that Canadian BTC holders accounted for 25% of the attributable losses.According to aggregated estimates from Galaxy Research, losses have reached as high as $110 million. We analyzed the geographic distribution of this ongoing hacking campaign. Users in Australia, the United States, and Thailand have also suffered significant losses.
Galaxy Digital Head of Research Alex Thorn stated that based on new victim reports received following the incident, the number of attackers exploiting the Coldcard vulnerability has reached at least 15.Thorn noted that information provided by victims helped the research team uncover previously unidentified attack activity. Unlike thefts from centralized exchanges, correlations between the attackers in this vulnerability exploit require confirmation through on-chain analysis and victim feedback.He added that a single victim reporting less than 1 BTC stolen helped the team discover a previously unknown attack, which siphoned approximately 12 BTC from 126 addresses.According to Galaxy Research's earlier estimates, the Coldcard vulnerability has led to at least three rounds of attacks, with losses amounting to approximately $100 million in BTC. Additionally, Galaxy has identified a suspected fourth round of attacks, which could bring total losses to approximately $130 million.Meanwhile, the incident has also sparked discussions regarding the security of Bitcoin self-custody. Dragonfly Managing Partner Haseeb Qureshi stated that "AI security hardening costing around $2" could potentially have prevented this vulnerability, and noted that some AI models were able to rediscover related vulnerabilities within a relatively short timeframe. However, industry insiders pointed out that current claims about the speed of AI discovering vulnerabilities lack rigorous blind testing and verification.Researchers believe that as AI model capabilities improve, the costs of vulnerability discovery and attacks in the crypto industry may continue to decline, requiring wallet developers to further strengthen code audits and security protections. (Cointelegraph)
Odaily News: Hardware wallet manufacturers Trezor and Foundation have warned that following the disclosure of a Coldcard firmware vulnerability, phishing attempts targeting hardware wallet holders have increased, with attackers soliciting recovery phrases and luring victims into downloading malware. Security firm Proofpoint has detected phishing emails impersonating Coldcard, inviting users to complete a "hardware audit" with links to a cloned website. After clicking, users download a batch file hosted on GitHub that installs the remote access tool ScreenConnect. Proofpoint stated that the fraudulent website also features a customer service chat window, where real people guide victims through the installation process. This remote access tool can provide attackers with a pathway to steal data and funds, or further deploy malicious programs such as ransomware. Galaxy Research has confirmed three rounds of theft since July 30, with high-confidence losses of 1,596 BTC, exceeding $100 million; if a fourth round not yet confirmed with victims is included, total losses could reach $130 million.
Odaily Planet Daily Report: Bitcoin hardware wallet manufacturer Coinkite disclosed in late July 2026 that a firmware build error introduced in March 2021 caused some Coldcard wallets to generate mnemonics from a smaller range, reducing the randomness of user private keys. Galaxy Research analysts stated that the Coldcard exploit occurred in multiple rounds, with observed Bitcoin losses rising from approximately $88 million to nearly $114 million within days. Researchers warned that other vulnerable addresses could still become targets, prompting many Coldcard users to move their Bitcoin. Coldcard is a Bitcoin-only wallet that supports offline signing via microSD card and optional QR codes. Launched in 2017, it has long been regarded as one of the security-focused Bitcoin hardware wallets.
Odaily News: Galaxy Research Head Alex Thorn analyzed that a new wave of Bitcoin sweeping attacks targeting Coldcard wallet addresses is underway, and cumulative losses from vulnerabilities related to Coldcard hardware wallets could approach $114 million. This attack primarily affects single-signature wallets, with no multi-signature wallets found to be impacted so far. No direct victim reports have been received yet; the assessment is mainly based on on-chain transaction pattern analysis, with some attack transactions still in an unconfirmed state.
Odaily News: According to monitoring by Galaxy's Head of Research, a suspected organized Coldcard attack is underway, with similar transactions still in the mempool awaiting confirmation. Previously confirmed transactions show RBF (Replace-By-Fee) enabled. Between blocks 960,778 and 960,792, 218 transactions occurred within approximately 2.5 hours, involving 462 victim addresses, 216 new destination addresses, and 388.92748828 BTC. None of the transactions had inputs predating the Coldcard firmware boundary. The sweep rate during this period was 13.8 times per block, compared to a baseline of 0.3 times per block in the pre-incident control window—approximately 45 times higher. The transaction topology is 1:1, with each victim address corresponding to a single new destination address. Only one destination address received two sweeps, and no consolidation addresses were observed. Some funds have already been swept to second-hop addresses.
Odaily News: Hardware wallet company Coinkite's Coldcard wallet series has experienced a seed generation randomness vulnerability, with threat actors stealing over 1,000 BTC in the past two days. Galaxy Research data shows that as of Saturday 17:36 ET, the incident involved 1,367 BTC, with losses exceeding $88 million. To notify potentially affected users, Coinkite sent security alerts to email addresses retained through its store and newsletter system since 2019. Coldcard confirmed that the emails originated from Coinkite and stated that it has contacted all reachable addresses to the best of its ability. Coinkite has faced criticism for retaining customer email data. The company stated that its public policy explains that purchase email addresses are saved so customers can log in and verify that other information has been cleared, but it did not specify a deletion timeline, saying these addresses would be kept "temporarily." Coinkite co-founder and CEO Rodolfo Novak previously stated that the company does not store customer information, deletes customer data 90 days after purchase, and offers anonymous purchase options.
Galaxy 研究主管 Alex Thorn 发文表示,围绕 Coldcard 钱包的攻击事件仍在持续发展,目前已经出现更多小型攻击者和模仿者,针对剩余 Coldcard 助记词展开攻击,他称通过协助已确认一名攻击事件中存款用户的身份,相关资金在 Duel 平台能够冻结之前已经被转出,而且涉及的资金并不属于 Galaxy Research 此前识别出的三轮主要攻击浪潮。 此前,Coldcard 疑似安全事件引发市场关注,多名研究人员发现部分由 Coldcard 生成的钱包地址出现异常资金转移。Galaxy Research 仍在持续追踪攻击地址,并提醒仍使用相关钱包种子的用户尽快采取安全措施。此次事件也进一步凸显了硬件钱包安全、私钥管理以及自托管风险防范的重要性。
Odaily News: According to monitoring by Galaxy's Head of Research, a victim's Coldcard wallet was compromised in a hacker attack involving nearly 30 BTC, of which 17 BTC were swapped for ETH via THORChain and subsequently deposited into Duel.comcasino. The victim and a researcher have sent emails to all known addresses associated with Duel.comcasino, requesting that the relevant funds be frozen, and provided all transaction and deposit information. The hacker deposited 229.72497255 ETH, valued at $445,000, into Duel.comcasino—funds originating from the Coldcard attack involving approximately 30 BTC. The victim stated that Duel.comcasino responded by saying that the police would need to contact their team. Duel.comcasino's anti-money laundering policy claims it enforces Know Your Customer (KYC) procedures and complies with all applicable laws. Duel.comcasino was notified within minutes of the deposit being completed. To date, Duel.comcasino has not frozen the relevant funds. Since most of the Western world had already passed midnight at the time of the incident, police reports cannot be filed until at least Monday. If Duel.comcasino fails to freeze the funds, the victim will pursue legal action against them. Duel.comcasino's X account has been suspended, and Galaxy's Head of Research has also flagged individuals on X suspected of being associated with the platform, including team members and dealers: @korraflow, @atrois7, @MiaMalkova.
Odaily News, Galaxy Research Head Alex Thorn posted on X platform, stating that the attack targeting wallet addresses with weak random numbers generated by Coldcard is still ongoing. Users who still hold funds in Coldcard single-signature wallets should immediately migrate to secure addresses. New victim addresses and attacker addresses are continuously being added to the investigation database, and Galaxy Research plans to release updated statistics on the number of affected addresses.He noted that the previously identified waves 1, 2, and 3 of the attack exhibit clear programmatic characteristics, and the stolen BTC currently remains in the attacker's addresses without any transfers. However, in recent times, smaller-scale attackers have begun exploiting the vulnerability to steal funds and move them through peeling chains, cross-chain services, and other methods. It is certain that single-signature wallet addresses generated by Coldcard after the March 2021 firmware upgrade are all potentially at risk, and users should migrate funds as soon as possible.Previously reported, Galaxy Research has disclosed that the Coldcard vulnerability attack has affected approximately 1,367.05 BTC (approximately $88.6 million), involving around 4,585 addresses.
Galaxy Research stated in a post on X that the attack targeting wallet addresses generated with weak randomness by Coldcard is still ongoing. The team urges users to immediately migrate funds from affected Coldcard single-signature wallets to secure addresses.They stated that approximately 600 suspected attacker addresses have been submitted to federal investigators, industry compliance bodies, and cross-industry cybersecurity investigators. These addresses are believed to hold funds stolen from Coldcard wallets with weak randomness.The team also noted that victims have proactively shared wallet addresses and transaction hashes, helping researchers establish on-chain attack patterns and further identify more affected wallets and attack addresses. Currently, multiple parties within the Bitcoin and crypto industry are assisting in user asset protection and attack tracing efforts.Galaxy Research previously stated in a post on X that a third wave of attacks suspected to target Coldcard-generated addresses has emerged, with 207.7294 BTC already transferred out. According to on-chain tracking data, the Coldcard wallet attack incident has so far involved approximately 1,367.05 BTC, valued at approximately $88.6 million, affecting 4,585 addresses.
According to monitoring by on-chain analysis firm Galaxy Research (@glxyresearch), the ColdCard wallet hacking incident has developed into a third wave, with an additional 207.73 BTC stolen. Currently, the three waves of attacks have cumulatively stolen 1,367.05 BTC (approximately $88.6 million), involving 4,585 addresses. On-chain data shows that the three waves of attacks exhibit highly similar characteristics: identical fund consolidation topology, identical P2WPKH target addresses, and mixed derivation paths. Each wave occurred approximately 27 hours apart, suggesting they were carried out by the same attacker, but there is currently no direct evidence to confirm this. Currently, all terminal addresses controlled by the hackers hold a total of 1,366.39 BTC (approximately $88.6 million), all of which are in an unspent state on-chain. Galaxy Research noted that the above data is based solely on Bitcoin block data and UTXO set analysis, and has not yet computationally verified whether the victim addresses have vulnerabilities due to low-entropy generation.