Galaxy Research has raised its confirmed estimate for the Coldcard hardware-wallet exploit to 1,789.28 BTC stolen from 8,865 addresses. The Bitcoin was worth approximately $114.7 million when taken and about $138.8 million at August 24 prices. The updated tally shows that the damage from the wallet-generation flaw has continued to grow as investigators identify additional affected addresses.
Most of the stolen Bitcoin has yet to move. Galaxy Head of Firmwide Research Alex Thorn said approximately 1,561 BTC, or 87.3% of confirmed losses, remains unmoved in attacker-controlled addresses. That large dormant balance leaves investigators with an ongoing opportunity to monitor the funds if they eventually approach exchanges, bridges or other identifiable infrastructure.
Weak Seed Entropy Exposed Wallets Without Physical Access
The breach originated in Coldcard’s seed-generation process. Coinkite’s official security advisory confirms that affected Mk2 and Mk3 firmware generated seeds with critically reduced entropy, while Mk4, Mk5 and Q devices were also affected before their respective fixes. Some Mk2 and Mk3 seeds contained only about 40 bits of entropy instead of the intended security level, making key reconstruction computationally feasible.
Galaxy’s forensic analysis of the Coldcard attacks found multiple distinct attacker footprints rather than evidence of one simple drain. Funds from later activity have moved through CoinJoin transactions and carefully constructed peel chains, while only a small portion has reached exchanges or cross-chain infrastructure. The different movement patterns complicate attribution and suggest that multiple actors were exploiting the same underlying weakness.
Losses were also highly uneven. Thorn’s latest figures put the median loss per affected address at just 0.00152 BTC but the average at 0.20184 BTC. Galaxy has received 221 direct victim reports covering 790.72 BTC, or 44.2% of confirmed losses. The large gap between median and average address losses shows how a relatively small number of higher-value wallets amplified the aggregate damage.
Existing Seeds Require Migration, Not Just a Firmware Update
Coinkite released patched firmware across affected Coldcard models, including version 4.2.0 or later for Mk2 and Mk3. However, installing corrected firmware does not repair recovery seeds generated with inadequate entropy, because the weakness is already embedded in the cryptographic material controlling those wallets.
Coinkite therefore advises affected users to install the appropriate fixed firmware, create an entirely new seed and transfer funds to newly derived addresses. Seeds supplemented with at least 50 independent, private dice rolls receive separate treatment under the company’s guidance. For exposed wallets, key rotation and asset migration remain the effective remediation rather than a conventional software patch alone.
Galaxy has shared identified attacker addresses with exchanges, compliance companies and law-enforcement agencies in hopes that funds can be intercepted if they reach centralized intermediaries. With nearly nine-tenths of the confirmed stolen Bitcoin still unmoved, the incident remains an active forensic and compliance problem even though confirmed new attack activity has slowed.

