Galaxy Research published updated figures on Monday showing 1,596 BTC stolen from 7,300 addresses across three confirmed attack waves and 14 smaller security incidents tied to a seed-generation flaw in Coldcard hardware wallets. The research firm said a suspected fourth wave has been identified but cannot yet be added to the confirmed total because victim confirmation remains incomplete.

If the fourth wave is validated, the total would reach 2,055 BTC, valued at approximately $130 million.

"While we have also identified a potential Wave 4, we have yet to receive specific victim confirmation of inclusion in this wave," Galaxy said. "Including it would bring the total to 2,055 BTC ($130m)."

Galaxy holds medium-high confidence that the suspected fourth wave is substantially the work of one attacker, but the firm declined to include it in its headline numbers without confirmed victim reports. Alex Thorn, Galaxy's head of firmwide research, first flagged the pattern on August 3, noting the transaction structure matched those seen in earlier confirmed waves. His running blockchain estimate later reached 448.7 BTC moving from 709 potential victim addresses, though Galaxy stressed that on-chain data alone cannot definitively confirm each victim or determine whether all activity stems from a single operator.

What the firmware flaw actually was and when it began

The attacks exploited a vulnerability in seeds generated on Coldcard Mk3, Mk4, Mk5, and Coldcard Q devices. Coinkite disclosed last week that the flaw originated in March 2021 during the integration of a new cryptographic library into its firmware. Instead of generating wallet seeds through the intended hardware-backed true random number generator, affected firmware mistakenly relied on a deterministic pseudo-random generator provided by MicroPython.

The hardware random number generator remained active elsewhere in the firmware, which allowed internal reviews to confirm its presence without revealing that wallet creation had silently switched to a weaker entropy source.

The team concluded that the vulnerable firmware called the deterministic MicroPython fallback instead of the STM32 hardware random number generator during seed creation, though it noted it had not completed full empirical testing of every affected device.

Coinkite estimates that affected Mk2 and Mk3 devices may offer roughly 40 bits of effective entropy, while vulnerable Mk4, Mk5, and Coldcard Q models may generate approximately 72 bits instead of the intended 128 bits.

Where the stolen Bitcoin sits right now

Galaxy said approximately 90% of the stolen coins have not moved.

"100% of coins in Waves 1, 2, and 3 have not moved," the firm stated. "It is essential that we continue to identify additional attacker addresses, especially as new, opportunistic attackers emerge, so that we can report their addresses to authorities."

The research firm has been providing confirmed attacker and victim addresses to US federal law enforcement agencies, crypto exchanges, and cyber investigation groups as the investigation expands. The coins remaining unmoved give investigators more time to track the funds, but Galaxy cautioned that new attackers could attempt to exploit the same vulnerability while affected devices remain in use.

Earlier blockchain analysis showed attack activity accelerating to approximately 13.8 wallet sweeps per Bitcoin block during the fourth suspected wave, up from roughly 0.3 sweeps per block before the incident began. Most stolen balances moved to newly created addresses rather than a central collection wallet, and some funds later passed through second-hop transactions that complicated on-chain tracing.

What Coldcard users still holding affected wallets need to do

Coinkite has released emergency firmware updates for all affected products. Version 4.2.0 covers Mk2 and Mk3 devices, version 5.6.0 covers Mk4 and Mk5, and version 1.5.0Q covers the Coldcard Q. The company has also destroyed all remaining inventory containing vulnerable firmware.

Installing the updated firmware does not fix wallets created before the update. Existing seed phrases generated under vulnerable firmware remain exposed. Coinkite recommends generating a completely new seed after updating the device, verifying a receiving address, sending a small test transaction first, and only transferring the remaining balance after the test confirms successfully.

Galaxy told users on X that the attacks are still active.

"The attack is ONGOING. If you are using a Coldcard and unsure whether it's safe, migrate your funds to a safe address at a custodian or exchange or a fresh seed," the firm wrote.

Users who still control compromised wallets with unconfirmed outbound transactions may be able to use Bitcoin's Replace-by-Fee mechanism to redirect their own coins with a higher-fee transaction before a miner confirms the theft, though this option carries no guarantee and only exists before confirmation.

Coinkite also said wallets created using at least 50 fair private dice rolls are not exposed by this specific random number generation flaw, and that a strong BIP-39 passphrase adds an additional security layer, while still recommending full migration.

Mastercard Closes $1.8B BVNK Stablecoin Deal | HODL FM NEWS
Mastercard closed its $1.8B BVNK acquisition Monday, folding stablecoin settlement infrastructure into its global network after Coinbase abandoned the deal.
hodl-post-image

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.