Key Takeaways
- The Coldcard hack has stolen 1,816 BTC, worth about $116 million, from 5,200+ addresses.
- Galaxy Research says Wave 4’s sweep rate hit 45 times the pre-incident baseline on August 3.
- Coinkite urges Coldcard users to move funds immediately after a 2021 firmware RNG flaw.
Four Waves in Four Days
What started as an estimated $30 million theft has more than tripled in less than a week. Bitcoin.com News first reported the exploit as it emerged, with the figure climbing with each new wave of transactions attackers have pulled from Coldcard-generated wallets: from an initial burst that moved $30 million in the opening ten minutes, to roughly $75 million after a second wave, to nearly $89 million as the theft spread to 4,500 addresses.
The figure now stands at approximately $116 million across 1,816 BTC pulled from more than 5,200 individual addresses. Galaxy Research, which has tracked the exploit in real time, confirmed a fourth wave on August 3 that alone moved roughly 449 BTC after corrections to earlier figures.
The company’s head Alex Thorn described the latest activity as a probable “fourth organized wave” of thefts, pointing to a sweep rate of 13.8 transfers per block against a pre-incident control window of just 0.3 transfers per block, or roughly 45 times normal baseline activity.

Thorn’s analysis suggests the pattern points to multiple groups racing in parallel across the vulnerable key space rather than a single attacker methodically expanding their operation, a detail that matters because it implies the theft could continue in bursts as different actors independently discover which addresses remain exposed.
Why the Random Number Flaw Matters
The root cause traces back further than this week, as a 2021 firmware update to certain Coldcard devices switched the wallet’s seed-generation process from a strong hardware-based randomness source to a software pattern that turned out to be predictable, meaning any wallet seed created on the affected firmware could, in theory, be guessed rather than brute-forced.
During the early scramble, ZachXBT declined to help trace the stolen funds, leaving victims and independent researchers racing against attackers who already understood exactly which addresses were vulnerable.
That head start is why the largest wallets were hit first. Attackers targeted the biggest balances within minutes of the exploit becoming active, and within roughly 25 minutes had already pulled hundreds of bitcoin from single-signature wallets before most holders had any indication their funds were at risk.
All compromised addresses trace back to wallet seeds generated after the flawed firmware shipped in March 2021, meaning the exposure window has existed for more than five years, quietly, until someone found and began exploiting it this month.
Coinkite’s Response and What Comes Next
Coinkite, the Canadian manufacturer behind Coldcard, has acknowledged the scale of the damage directly. In a statement addressing the ongoing thefts, the company said “the last three days have been some of the hardest in this company’s history, and for a lot of the people reading this, they’ve been something much worse,” and strongly advised anyone who generated a wallet seed on a Coldcard device to move their funds to a new, safely generated wallet as soon as possible.
Victims still working through the process have a narrow window to attempt Replace-By-Fee transactions on unconfirmed transfers, though that option only helps if an attacker’s sweep has not already confirmed onchain.
Lastly, industry personnel like Anthony Pompliano have pushed back on the narrative that the hack was on bitcoin itself, arguing that the flaw sat squarely in Coldcard’s firmware rather than the BTC protocol.







