CryptoMediumUpdated×7•Originally published 2 August 2026•Updated 3 August 2026•
1 min read

Coldcard Wallet Exploit Losses Surge to $89 Million in Third Wave of Attacks

Key Facts

1Losses from the Coldcard firmware exploit have risen to approximately 1,367 BTC, valued at nearly $89 million.
2Galaxy Research confirmed a third wave of thefts targeting 1,912 additional addresses between July 31 and August 1.
3Attackers shifted tactics in the third wave, using separate P2WSH vaults to obscure the trail of stolen funds.

Amid escalating concerns over cold storage security, the Coldcard firmware exploit has intensified, with total losses reaching approximately 1,367 BTC, valued at nearly $89 million. Galaxy Research confirmed a third wave of automated thefts targeting 1,912 additional addresses between July 31 and August 1, bringing the total number of compromised wallets to 4,585 since the attack began.

Technical analysis indicates that attackers shifted tactics during the third wave, utilizing P2WSH vaults to obscure the trail of stolen funds and complicate on-chain tracking. Per market data and analyst reports, the flaw originates from firmware shipped in March 2021; Binance founder Changpeng Zhao has since warned that hardware wallets are not 100% foolproof, especially as firmware updates cannot fix seeds already generated on compromised devices.

Traders are monitoring upcoming macro catalysts, such as the US CB Consumer Confidence data on July 28, 2026, which may influence broader risk appetite across both digital and traditional asset classes.

Latest Updates · 6

  1. Notable·

    Update: Kraken's security chief has revealed new technical details indicating the vulnerability persisted undetected for five years due to an auditing oversight; auditors verified the presence of the random number generator (RNG) but failed to confirm it was actually being called by the software. This revelation highlights a significant gap in security standards that left devices exposed for an extended period.

  2. Notable·

    Update: Alex Thorn, head of research at Galaxy, has warned of a suspected fourth wave of attacks targeting an additional 389 BTC. Researchers noted that unconfirmed transactions may provide a brief window of opportunity for affected users to secure their funds before the thefts are finalized.

  3. Notable·

    Update: Alex Thorn, head of research at Galaxy, has warned of a suspected fourth wave of attacks targeting an additional 389 BTC. Analysts suggest that unconfirmed transactions may offer Coldcard users a brief window of opportunity to secure their funds before the automated thefts are finalized on-chain.

  4. Notable·

    Update: The Coldcard exploit has triggered a flight from Bitcoin as investor confidence wavers, leading to noticeable outflows. Meanwhile, the digital asset sector is closely watching the US Senate, where the Clarity Act faces a critical voting deadline in just five days, representing a major legislative catalyst for crypto regulation.

  5. Notable·

    Update: The crisis has taken a new turn as an on-chain laundering service offer was publicly sent to the attacker's address. Simultaneously, recovery efforts have faced setbacks following reports from users that emergency firmware updates have rendered their hardware units completely unusable, or 'bricked,' during the patching process.

  6. Major·

    Update: Manufacturer Coinkite issued a warning on July 30 stating that a software error caused seed phrases to be generated with insufficient randomness, enabling the exploit. This event has triggered the largest movement of Bitcoin since the FTX collapse, significantly distorting broader market signals.