Coldcard exploit drains more than $100 million in Bitcoin, says Galaxy
Coldcard has issued an urgent warning for users to migrate Bitcoin from affected wallets after confirming that an exploit targeting vulnerable firmware is still ongoing.
Galaxy Research said confirmed losses from the Coldcard wallet exploit have surpassed $100 million after identifying 1,596 stolen Bitcoin across three verified attack waves and several smaller incidents.
🚨LOSSES FROM COLDCARD HACK EXCEED $100M
High confidence 1,596 BTC has been stolen from ~7300 addresses across 3 confirmed waves + more 14 smaller incidents.
If we add suspected (but unconfirmed), the total balloons to $130m (2k BTC).
More in the thread below 👇 pic.twitter.com/RAl3ib67qa
— Galaxy Research (@glxyresearch) August 3, 2026
According to the firm, roughly 7,300 wallet addresses were affected in the confirmed attacks, while 14 additional exploit clusters have emerged through ongoing victim reports. Investigators said 73 victims contacted them to help trace stolen Bitcoin, suggesting the vulnerability is being exploited by multiple actors.
Researchers also believe a fourth large attack wave likely occurred, although it has yet to be confirmed by affected users. Including the suspected incident would increase estimated losses to approximately 2,055 BTC, valued at around $130 million.
In a statement issued this morning, Coldcard wallet maker Coinkite warned users to urgently secure their Bitcoin, saying the exploit that has drained up to $114 million from self-custodied wallets continues to target vulnerable devices.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Please treat this as urgent. Migrate your funds. Follow the advisory for your model, upgrade your device, generate a new seed, and carefully move your funds.
Help spread the word, especially to people who are less online and may not see this update.
The threat is still ongoing. https://t.co/cbJxJles8x
— COLDCARD (@COLDCARDwallet) August 4, 2026
Users of affected Coldcard models were advised to install updated firmware, create a new seed phrase and move funds to a new wallet, as compromised seeds remain vulnerable until manually replaced.
The company said wallets created using its optional dice-based entropy method are not affected by the vulnerability.