Galaxy Research Details Bitcoin Losses From Coldcard Vulnerability

Source: blockonomi2026/08/18 17:52
Analysis
Galaxy Research's investigation into the Coldcard firmware vulnerability marks a significant step in quantifying a long-running Bitcoin theft that traces back to a March 2021 entropy flaw in wallet seed generation. The research confirms that attackers exploited predictable entropy to recreate private keys, with confirmed losses now exceeding $115 million across 192 victims, while the broader public dataset points to roughly 1,778.6 Bitcoin held across 8,680 linked addresses. The identification of distinct attacker fingerprints, including transaction waves and grouping patterns, suggests multiple actors or coordinated campaigns rather than a single operator, which could complicate recovery and attribution efforts. The ongoing investigation may expand the confirmed victim count and loss figures as more affected addresses are linked to individuals, and the findings could pressure hardware wallet manufacturers to strengthen firmware auditing and disclosure practices. Watch for updates to the public dataset, potential law enforcement involvement, and whether other wallet products share similar entropy-generation weaknesses.

If you have any feedback or questions about this content, please contact us at crypto.news@kcex.com

TLDR

  • Galaxy Research investigated a Bitcoin theft tied to a 2021 Coldcard firmware flaw
  • 192 victims have confirmed losses of about 714.8 Bitcoin in the public dataset
  • Total losses across all linked addresses have climbed past $115 million
  • Attackers left different transaction habits, grouped into waves and footprints
  • Most of the stolen coins were generated between 2021 and 2022

It has been 18 days since the Coldcard exploit first came to light on July 30. The impact is still being felt by Bitcoin holders.

Galaxy Research spoke with more than 200 victims on August 16 to learn more about the theft. Their goal was to understand how the attackers worked.

The stolen coins were traced back to a single date. That date is March 17, 2021, when the flawed Coldcard firmware was first released.

At that time, Bitcoin had reached a block height of 674,951. This detail matters because it links the exploit directly to a flaw in how wallet seeds were created.

How the Theft Happened

The flaw allowed bad actors to predict or recreate the entropy used to generate a wallet seed. In simple terms, this let them guess or rebuild the private keys tied to affected wallets.

Galaxy’s research shows that most of the theft activity took place between 2021 and 2022. This was the period when the largest number of stolen addresses first appeared.

Galaxy published a public dataset listing 8,680 addresses connected to the theft. These addresses hold roughly 1,778.6 Bitcoin combined.

Only a small share of those addresses have been directly linked to victims who came forward. Even so, the numbers are large.

Out of the public dataset, 192 people have confirmed losses. Their cases involve about 1,790 addresses and 714.8 Bitcoin.

Earlier reporting had placed total losses at more than 1,596 Bitcoin across roughly 7,300 addresses. At the time, that was valued at over $100 million.

Using Bitcoin’s price on August 16, the total value of losses has now passed $115 million.

Tracking the Attackers

Researchers identified several patterns, or fingerprints, in how the stolen funds moved. These patterns include block timing, transaction fees, lock times, and destination addresses.

One group, labeled Wave 1, stole about 1,082.65 Bitcoin from blocks 960,183 through 960,191. This group typically moved one victim’s coins per transaction into four collection addresses.

Other groups worked differently. Wave 3 handled 63 victims, while Wave 2 handled only 19.

A separate pattern called Footprint E grouped as many as 795 victims into a single transaction. The median number of victims per transaction for this group was 118.

The way stolen funds were spread out also varied. Some groups scattered the coins across hundreds of addresses, while others kept the funds concentrated in just a few wallets.

As of August 16, the confirmed losses stand at more than $115 million. Galaxy Research says the investigation into the full scope of the theft is ongoing.

The post Galaxy Research Details Bitcoin Losses From Coldcard Vulnerability appeared first on Blockonomi.

Disclaimer: The articles reposted on this website are sourced from public platforms and are for reference only. These articles do not represent the views or opinions of KCEX. All copyrights belong to the original authors. If you believe that any reposted article infringes upon the rights of a third party, please contact crypto.news@kcex.com for removal. KCEX makes no representations or warranties regarding the timeliness, accuracy, or completeness of reposted articles, and shall not be liable for any actions or decisions made based on such content. Reposted materials are for informational purposes only and do not constitute advice, endorsement, or basis for any commercial, financial, legal, and/or tax decisions.