Hackers linked to the Coldcard wallet exploit are still holding the vast majority of the Bitcoin stolen in the attack, giving blockchain investigators a relatively clear view of where much of the funds remain.
Galaxy Research has traced approximately 1,789 BTC taken from 8,865 Bitcoin addresses in the incident. The cryptocurrency was worth about $114.7 million when it was stolen, while its value has since risen to roughly $138.8 million.
Most importantly, around 1,561 BTC or 87.3% of the identified stolen funds has not moved from attacker-controlled collection and holding addresses.
Researchers are continuing to monitor those wallets while sharing identified addresses with exchanges, compliance companies and law enforcement agencies.
Galaxy Research Traces 1,789 BTC to Coldcard Hack
Galaxy Research’s investigation has linked 1,789.28 BTC to the Coldcard exploit, according to figures shared by the firm’s head of research, Alex Thorn.
The funds were stolen from 8,865 addresses across several attack waves.
At the time of the thefts, the identified Bitcoin was valued at approximately $114.7 million. Due to subsequent changes in Bitcoin’s market price, Thorn estimated that the same amount was worth around $138.8 million at the time of his latest update.
Despite the scale of the theft, attackers have moved only a relatively small portion of the attributed funds.
Approximately 1,561 BTC remains sitting in wallets controlled by the attackers.
That represents around 87.3% of the total confirmed Bitcoin attributed to the exploit.
Bitcoin From the First Three Attack Waves Has Not Moved
Investigators have identified several different waves of attacks associated with the Coldcard incident.
According to Galaxy Research, all of the Bitcoin stolen during the first three identified waves remains unmoved.
That is significant because Bitcoin’s public blockchain allows investigators to continuously monitor known addresses.
As long as the stolen funds remain parked in those wallets, researchers maintain a clear record of their location.
If the attackers eventually move the Bitcoin to exchanges or other identifiable services, those transactions may create opportunities for exchanges, compliance companies or authorities to intervene.
Galaxy has therefore distributed known attacker addresses to relevant organizations so the wallets can be monitored across the cryptocurrency ecosystem.
Some Later Stolen Bitcoin Has Started Moving
The behavior changes when looking at some of the later attacks.
Galaxy researchers have identified stolen funds moving through techniques including CoinJoin transactions and peel chains.
These methods do not make Bitcoin disappear from the blockchain. Instead, they are designed to make transaction histories more difficult to interpret and follow.
CoinJoin combines Bitcoin transactions from multiple participants, making it harder to determine which output corresponds with a specific original input.
Peel chains work differently.
An attacker repeatedly moves portions of a larger Bitcoin balance into new addresses, creating a longer and more complicated transaction trail.
Investigators can still analyze these transactions, but the process becomes more challenging as the number of addresses and intermediate transfers increases.
Thousands of Bitcoin Addresses Were Affected
The Coldcard exploit affected a large number of individual Bitcoin addresses.
Across the 8,865 addresses identified by Galaxy, the median loss was approximately 0.00152 BTC.
The average loss per affected address was significantly higher at around 0.20184 BTC.
Researchers also found that much of the Bitcoin had remained untouched for years before being stolen.
The median dormancy period across affected addresses was approximately 3.2 years, while the average was around 3.6 years.
Long periods of inactivity may indicate that many affected wallets were being used primarily for long-term Bitcoin storage rather than frequent transactions.
That makes the incident particularly notable because hardware wallets are often chosen specifically by long-term holders seeking stronger self-custody security.
Victim Reports Show Much Larger Individual Losses
Galaxy has also received information directly from people affected by the exploit.
Researchers received 221 victim reports covering approximately 790.72 BTC.
That represents about 44.2% of all Bitcoin currently attributed to the incident.
Among these reports, the median loss was approximately 1.04 BTC, while the average reported loss reached around 3.58 BTC.
Thorn clarified that the median figure means at least half of the 221 reporting victims lost 1 BTC or more.
The Bitcoin included in direct victim reports had also remained inactive for years before the attack.
Its median dormancy period was roughly 3.25 years.
These numbers suggest some victims were using Coldcard devices to secure substantial long-term Bitcoin holdings.
Total Coldcard Losses Could Be Even Higher
The confirmed 1,789 BTC figure may not represent the complete scope of the incident.
Galaxy has identified additional addresses that researchers consider potentially connected to the exploit but have not yet confirmed with the same level of confidence.
Including those medium-confidence addresses would increase the estimated total to approximately 1,824 BTC.
That amount was worth around $140 million at the time of the respective thefts, according to the research.
The estimate has continued to evolve as investigators identify new victim addresses and recognize additional patterns associated with the attacks.
This is common in large cryptocurrency investigations because researchers often need to connect transactions, wallet behavior and victim reports before confidently attributing an address to a particular incident.
Researchers Link the Exploit to Weak Seed Generation
Earlier investigations by blockchain intelligence firm TRM Labs connected the Coldcard thefts to a problem involving cryptocurrency seed generation.
According to TRM Labs, a firmware build configuration error introduced in March 2021 caused certain affected Coldcard devices to use a weaker software-based random number generator under particular circumstances instead of relying fully on hardware-generated entropy.
Secure randomness is essential when generating cryptocurrency wallet seeds.
A seed phrase ultimately determines the private keys controlling a user’s cryptocurrency. If the random information used to generate that seed is sufficiently unpredictable, guessing the private keys should be computationally unrealistic.
But if the randomness is weak, the number of possible seeds an attacker needs to test may become dramatically smaller.
TRM Labs said the weakness could reduce key security enough that attackers with sufficient computing resources might recover private keys through brute-force techniques without physically possessing the Coldcard device.
Why Weak Randomness Is Dangerous for Crypto Wallets
Cryptocurrency wallets rely heavily on entropy, or randomness, when generating private keys and recovery phrases.
A properly generated seed should be practically impossible for another person to guess.
If a wallet produces seeds using predictable or insufficiently random information, however, the apparent complexity of the recovery phrase can become misleading.
An attacker does not necessarily need to guess every theoretically possible recovery phrase.
Instead, if researchers or criminals identify how the faulty random number generator behaved, they may be able to narrow the search to a much smaller range of possibilities.
Powerful computing hardware can then test potential keys until it finds addresses containing Bitcoin.
This type of weakness is particularly concerning because it can potentially be exploited remotely without stealing or physically tampering with the hardware wallet.
Updating Firmware May Not Protect an Already Weak Seed
One of the most important implications of the reported Coldcard issue is that simply updating a device may not fix an existing vulnerable wallet.
If a recovery seed was originally created using inadequate randomness, its underlying private keys remain derived from that same potentially weak seed.
Installing newer firmware does not change those keys.
According to TRM Labs’ analysis, affected users would instead need to generate an entirely new seed using secure hardware and move their Bitcoin to addresses derived from the new recovery phrase.
The distinction is important because firmware updates can prevent a vulnerability from affecting newly created seeds without necessarily protecting cryptocurrency already stored under previously generated keys.
Exchanges and Law Enforcement Are Tracking Attacker Addresses
Galaxy Research is continuing to distribute identified attacker wallets to cryptocurrency exchanges, compliance providers and law enforcement agencies.
This creates potential checkpoints if stolen Bitcoin eventually enters centralized platforms.
Cryptocurrency exchanges generally maintain customer accounts and transaction records and may be able to freeze or restrict suspicious assets when required under applicable legal and compliance processes.
For attackers, moving funds into such services can therefore create additional exposure.
That may help explain why such a large percentage of the stolen Bitcoin has remained unmoved, although researchers have not confirmed the attackers’ motivations.
The 1,561 BTC still parked in known wallets gives investigators an opportunity to immediately detect future movements.
Multiple Attackers May Have Been Involved
Researchers have also noticed differences in how stolen Bitcoin moved during various stages of the incident.
TRM Labs previously reported that much of the stolen cryptocurrency was being consolidated into a relatively small number of addresses.
However, differences in transaction structures between attack waves raised the possibility that more than one attacker may have exploited the weakness.
That remains a possibility rather than a confirmed attribution.
No specific hacking organization or individual has been publicly identified as responsible for the entire Coldcard incident.
Investigators will likely continue comparing wallet behavior, transaction timing and laundering techniques to determine whether the different waves were connected to one group or several independent attackers.
Coldcard Hack Raises Questions About Hardware Wallet Security
The incident has attracted particular attention because Coldcard is a hardware-wallet brand built specifically around Bitcoin self-custody.
Coldcard devices emphasize offline key storage and air-gapped transaction workflows designed to reduce exposure to internet-connected threats.
Coinkite released the Coldcard MK5 in 2026, introducing hardware changes including a larger display, redesigned buttons and improved NFC functionality while retaining its Bitcoin-focused design.
But the latest incident highlights an important reality about hardware-wallet security.
Strong secure elements, offline signing and physical protections cannot fully protect funds if the private keys themselves were generated using insufficient randomness.
For cryptocurrency users, secure seed generation is therefore just as critical as protecting the hardware device after the wallet has been created.
Hardware Wallet Security Faces Growing Scrutiny
Coldcard is not the only cryptocurrency wallet product to face security attention this year.
Researchers have disclosed several wallet-related vulnerabilities involving different attack methods.
Coinspect previously reported a weakness known as “Ill Bloom” involving poor randomness during recovery phrase generation in several software wallets.
In another case, Ledger’s Donjon security researchers demonstrated a sophisticated laser-based attack against a Tangem wallet card.
That attack required physical possession of the device, specialized technical knowledge and expensive laboratory equipment, making it fundamentally different from the reported Coldcard seed-generation problem.
The Coldcard incident stands out because investigators believe compromised seeds could potentially be attacked computationally without requiring physical access to a victim’s device.
1,561 BTC Remains Under Attacker Control
For now, the biggest development in the investigation is what the hackers have not done.
Approximately 87.3% of the confirmed stolen Bitcoin remains unmoved.
The 1,561 BTC sitting in attacker-controlled wallets remains visible on Bitcoin’s public ledger, allowing investigators to monitor those addresses continuously.
Some later stolen funds have already entered more complicated transaction patterns involving CoinJoin and peel chains, suggesting at least some effort is being made to obscure their movement.
But the largest portion of the stolen assets remains parked.
Galaxy Research is continuing to track those funds while exchanges, compliance firms and authorities receive updated information about identified attacker wallets.
Any future movement of the 1,561 BTC could therefore provide investigators with new evidence and potentially create opportunities to identify where the attackers attempt to move or convert the stolen cryptocurr











































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































