discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Coldcard Bitcoin theft tops $100M across 3 confirmed attack waves: Galaxy

Confirmed losses from a Coldcard wallet incident have surpassed $100 million, with 1,596 Bitcoin stolen across three major attack waves and 14 smaller incidents, according to Galaxy Research.

By Ezra Reguerra·Aug 4·cointelegraph.com·3 min read

Intelligence analysis by Gemini 2.5 Flash

Coldcard Bitcoin theft tops $100M across 3 confirmed attack waves: Galaxy
Image: cointelegraph.com

Galaxy Research reports that a series of attacks targeting Coldcard hardware wallets has resulted in over $100 million in stolen Bitcoin from approximately 7,300 addresses. While 90% of the stolen funds remain unmoved, investigators are examining a suspected fourth wave that could push total losses to $130 million, prompting urgent warnings for users to secure their assets.

Why it matters

This incident highlights significant security vulnerabilities in a prominent hardware wallet, raising concerns for Bitcoin holders and underscoring the critical importance of robust security practices and vigilance in the cryptocurrency space.

Imagine your special digital money is kept in a super-secure digital safe, like a Coldcard. But sneaky digital thieves found a way to pick the lock, not just once, but three times, stealing over $100 million worth of Bitcoin. Even though most of the stolen money hasn't been moved yet, it's a big warning for everyone to double-check their digital safes and move their money if they're worried.

Analysis

The Scale of the Coldcard Breach

The Coldcard wallet incident has escalated significantly, with confirmed losses now exceeding $100 million. Galaxy Research, a prominent analytical arm in the crypto space, has identified 1,596 Bitcoin (BTC) stolen across three distinct major attack waves, alongside 14 smaller, opportunistic incidents. This widespread breach has impacted approximately 7,300 unique addresses, indicating a broad compromise rather than isolated incidents. The sheer volume of affected addresses and the substantial monetary value underscore the severity of the vulnerability exploited.

The initial findings from Galaxy Research, published earlier, traced 1,367 BTC across 4,585 addresses. The updated figures reflect a more comprehensive understanding of the attack's scope, gathered from 73 victims who directly contacted researchers. These victim reports were crucial in confirming the initial major attacks and subsequently identifying the smaller footprints, suggesting a multi-faceted approach by the attackers, potentially involving both sophisticated, coordinated efforts and opportunistic exploits.

Galaxy's Ongoing Investigation

Galaxy Research's investigation is ongoing, with a particular focus on a suspected fourth wave of attacks. This potential fourth wave could elevate the total losses to 2,055 BTC, equivalent to approximately $130 million at current market values. While this event has not yet been included in the confirmed estimate due to a lack of direct victim confirmation, Galaxy expresses "medium-high" confidence that it represents genuine attacker activity. This cautious approach highlights the meticulous nature of their forensic analysis, prioritizing verified data.

A critical aspect of the investigation is the status of the stolen funds: 90% of the Bitcoin, including those from the first three confirmed incidents, remains unmoved. This dormancy could be a double-edged sword; while it offers a slim hope for potential recovery or seizure by law enforcement, it also suggests a patient and sophisticated attacker who may be waiting for opportune moments to liquidate the assets. Attacker and victim addresses have been shared with US federal law enforcement, crypto exchanges, and cyber-investigation companies, indicating a coordinated effort to track and potentially recover the funds.

Implications for Hardware Wallet Security

The Coldcard incident serves as a stark reminder of the persistent security challenges within the cryptocurrency ecosystem, even for devices traditionally considered highly secure. Hardware wallets are designed to protect private keys offline, making online theft extremely difficult. The nature of this exploit, which allowed for such a large-scale theft, will undoubtedly prompt a deeper examination of hardware wallet design, firmware vulnerabilities, and user interaction security protocols across the industry.

The ongoing nature of the attacks, as warned by Galaxy, necessitates immediate action from Coldcard users. The recommendation to migrate funds to a safe address highlights the urgency and the potential for further compromises. This event will likely lead to increased scrutiny of hardware wallet manufacturers, pushing for enhanced security audits, transparent vulnerability disclosures, and more robust user education on best practices for protecting their digital assets. The incident underscores that even with advanced security tools, vigilance and proactive measures remain paramount for crypto investors.

Key points

  • Confirmed losses from the Coldcard wallet incident have exceeded $100 million, with 1,596 Bitcoin stolen.
  • The theft occurred across three major attack waves and 14 smaller incidents, affecting about 7,300 addresses.
  • Galaxy Research identified a suspected fourth wave that could increase total losses to 2,055 BTC, or $130 million.
  • Approximately 90% of the stolen Bitcoin remains unmoved, with addresses shared with law enforcement and exchanges.
  • Coldcard users are urged to migrate their funds immediately due to ongoing attacks.
The Upside

The fact that 90% of the stolen Bitcoin remains unmoved offers a glimmer of hope for potential recovery, especially with law enforcement and cyber-investigation companies now involved. This could lead to successful asset freezes or seizures if the attackers attempt to cash out, potentially mitigating some of the losses for victims.

The Downside

The ongoing nature of the attacks and the identification of a suspected fourth wave highlight the persistent vulnerability, suggesting that more users could fall victim and total losses might increase significantly. The inherent difficulty in recovering stolen cryptocurrency, even if unmoved, also presents a major challenge for victims.

Originally reported at

cointelegraph.com

Discernion covers the story. Read the full piece at the source.

Tagscryptosecuritybitcoinwallet-securitycybersecurityhacks

Author

Ezra Reguerra

Intelligence analysis by

Gemini 2.5 Flash

Published

Aug 4, 2026

Source

cointelegraph.com

Share

Topics

cryptosecuritybitcoinwallet-securitycybersecurityhacks

Related

More from this desk

A wad of dollar bills changes hands (Shutterstock)
Aug 4·coindesk.com

Flare's Wrapped XRP Wins Approval in a $280 Million RLUSD Lending Vault

XRP holders can now use wrapped XRP (FXRP) as collateral to borrow Ripple's RLUSD stablecoin on Ethereum. A $280 million lending pool managed by Sentora approved FXRP, opening a new isolated market on Morpho Blue.

Aug 4·cointelegraph.com

Crypto firms still seeking frontier AI access; only select few have it

Many major crypto firms are struggling to gain access to advanced AI models for cybersecurity, creating a security divide. While some select entities have secured access, most are left to defend against AI-assisted threats with less capable tools.

Solana sign (CoinDesk)
Aug 4·coindesk.com

New Solana Proposal Aims to Ramp Up Daily SOL Burns From $47,000 to $650,000

Solana validators are signaling support for proposals to reduce SOL issuance and increase SOL burns. SIMD-0553 could raise daily burns to $650,000 by implementing resource-based transaction fees.

Aug 4·cointelegraph.com

Bitmine Adds $19.6M in ETH, Repurchases 4.5M Shares

Bitmine, an ether treasury company, has added $19.6 million in ETH to its holdings and repurchased 4.5 million of its shares as part of its crypto accumulation and stock-buyback program.