Coldcard Bitcoin Exploit Triggers Devastating $88 Million Plunder
A Coldcard Bitcoin Exploit targeting Bitcoin hardware wallets has grown to $88 million after a third wave of thefts drained funds from 4,585 addresses, according to Galaxy Research on August 2. The observed losses now stand at roughly 1,367 BTC, up sharply from figures reported in earlier waves.
The attack is one of the largest hardware wallet compromises in Bitcoin’s history.
Key Takeaways
- Galaxy Research tracked 4,585 compromised Bitcoin addresses as of August 2, with observed losses reaching roughly 1,367 BTC
- The attack unfolded in three distinct waves, an unusual pattern for large-scale cryptocurrency wallet compromises
- Bitcoin wallet migration volume hit a two-year high after news of the exploit spread on August 2
- Coinkite has not yet issued a public post-mortem identifying the root cause of the exploit
Coldcard Bitcoin Exploit Spreads Across 4,585 Victim Addresses
The Coldcard Bitcoin Exploit has unfolded in three distinct waves, with each successive round pulling in a new cluster of affected addresses. Galaxy Research tracked 4,585 compromised BTC (BTC) addresses as of its latest count.
The attack does not appear to target a single vulnerability introduced in one firmware release but instead affects wallets across a range of configurations.
A hardware wallet is a physical device that stores the private keys needed to authorize Bitcoin transactions. Private keys never leave the device in a correctly functioning wallet, which is why hardware wallets are considered the most secure consumer storage option.
The Coldcard Bitcoin Exploit undermines that guarantee. Attackers have somehow obtained or derived private keys from affected devices, allowing them to sign and broadcast transactions that move funds to attacker-controlled addresses without the victim’s involvement.
Also Read: Strategy’s July 30 Filing Discloses 843,775 BTC, and Nobody Else Is Remotely Close
Why Coldcard Sits At The Heart Of Bitcoin Self-Custody
Coinkite, the Canadian company that manufactures Coldcard, built its product specifically for the most security-conscious Bitcoin holders.
Coldcard devices are air-gapped, meaning they can sign transactions without ever connecting directly to an internet-enabled computer. That design philosophy made them a default recommendation among Bitcoiners who distrust exchange custody after the collapse of FTX in 2022.
The breach therefore lands hardest on users who took extra precautions.
Victims are not people who left coins on an exchange. They are people who bought dedicated hardware precisely to avoid that risk.
The psychological damage to Bitcoin’s self-custody narrative may outlast the financial losses.
On-chain metrics reacted quickly. Bitcoin wallet migration volume hit a two-year high after news of the Coldcard Bitcoin Exploit spread on August 2, as holders rushed to move funds from Coldcard devices to alternative storage.
How Three Waves Turned A Coldcard Bitcoin Exploit Into An $88 Million Catastrophe
The three-wave structure of the Coldcard Bitcoin Exploit is unusual in cryptocurrency security incidents.
Most large-scale wallet compromises unfold as a single coordinated drain. A multi-wave pattern suggests attackers are working through a list of compromised keys methodically, possibly rate-limiting their activity to avoid triggering exchange screening tools that flag sudden inflows from clustered addresses.
The $88 million figure represents observed losses only.
Galaxy Research uses blockchain tracing to identify transaction patterns consistent with the exploit. Actual losses could be higher if some victims have not yet been identified or if some funds moved through mixing services before researchers could tag them.
At roughly $64,000 per BTC at the time of writing, 1,367 BTC equals approximately $87.5 million.
That figure will shift with Bitcoin’s price, but the number of coins stolen is fixed on-chain and independently verifiable.
What Coldcard Holders Must Do Now
Coinkite has not yet issued a public post-mortem identifying the root cause of the Coldcard Bitcoin Exploit. That silence is itself a risk signal.
Without knowing whether the vulnerability lies in firmware, the key generation process, supply-chain tampering, or a third-party software integration, affected users cannot assess whether a device they own is compromised.
The safest immediate step for any Coldcard holder is to treat the private keys stored on the device as potentially exposed and generate fresh keys on a different hardware wallet model or a clean air-gapped machine. Funds should be moved to addresses derived from those fresh keys before any further delay.
Galaxy Research’s three-wave tracking also implies attackers still hold an undisclosed number of additional compromised keys.
A fourth wave remains plausible until Coinkite confirms the scope of the Coldcard Bitcoin Exploit and releases a verified patch.
Hardware wallet security has faced growing scrutiny in 2026 as Bitcoin’s price appreciation has raised the dollar value of coins stored on consumer devices. An attack that would have yielded $10 million at 2020 prices now yields nine times that on the same BTC volume.
That arithmetic makes the self-custody attack surface increasingly attractive to sophisticated adversaries.
Read Next: Anthropic Calls Some Open-Weights Releases Irreversible, a Two-Year Fight Just Reignited
