Galaxy Research says a third wave of attacks tied to a Coldcard hardware wallet firmware flaw has pushed observed Bitcoin losses to approximately 1,367 BTC, worth about $88.6 million, and Galaxy’s head of research, Alex Thorn, is urging anyone with a single-signature Coldcard address created after March 2021 to move funds immediately.
What You Need to Do Right Now
Alex Thorn, Galaxy Research’s head of research, wrote on X on August 1 that “an active sweep attack is underway against all single-signature Coldcard addresses created after the March 2021 firmware update,” and that affected users should move funds to a different address without delay.
Coinkite, Coldcard’s manufacturer, has released fixed firmware for every affected model and published an advisory instructing users to install the fix, generate a completely new seed, verify the new backup and receiving address, and send a small test transaction before moving any remaining balance, keeping the old backup until migration is confirmed.
Critically, installing the new firmware alone does not protect existing funds, as it only corrects how future seeds are generated and cannot add missing entropy to an existing recovery phrase.
Inside the Vulnerability
Coinkite said a series of firmware integration errors, introduced in a March 2021 code change, prevented the device’s hardware random-number generator from properly contributing to seed creation, with a software fallback supplying predictable output instead.
The company estimated that affected Mk2 and Mk3 seeds have only about 40 bits of effective search space, and that later Mk4, Q, and Mk5 models, despite adding secure-element entropy, came in at around 72 bits rather than the intended 128, with estimates the company says may still change as testing continues.
The affected range covers Mk2 and Mk3 firmware 4.0.1 through 4.1.9, and Mk4 and Mk5 seeds created before standard version 5.6.0, plus Q seeds created before version 1.5.0Q.
Seeds generated from at least 50 fair, independent dice rolls are not considered exposed by this specific issue alone, though Coinkite still advises migration regardless.
Three Waves, Three Different Patterns
The first wave, on July 30, drained 1,082.65 BTC from 1,196 victim addresses in just 41 minutes, between roughly 1:10 and 1:51 a.m. UTC.
A second wave the next day removed 76.16 BTC from another 1,478 victim addresses, sharing enough technical similarities with the first, including the same output format, shared collector addresses, and derivation-path behavior, occurring 27 hours apart, that Galaxy believes the same operator likely carried out both.
A third wave, identified more recently, drained roughly 208 BTC from 1,912 victim addresses, averaging just over a tenth of a Bitcoin per victim, a sharp drop from wave one’s average of nearly a full coin, suggesting the highest-value vulnerable wallets have already been emptied.
The third wave behaved differently in ways that matter for tracking it, because rather than consolidating funds into a handful of shared addresses the way the first two waves did, it sent each victim’s coins to a separate destination, parked in pay-to-witness-script-hash outputs rather than the simpler format used before, and batched an average of six to seven victims per sweep rather than draining one address at a time.
Galaxy said it’s confident each individual wave reflects a single operator, but stopped short of confirming whether the same attacker is behind all three, since onchain data alone can’t make that determination.
None of the funds sitting in the wave three destination addresses have moved as of the most recent reporting.
A Widening, Evolving Threat
Thorn said the attacks appear to follow programmed patterns that may have been generated using large language models (LLMs), and that smaller, opportunistic attackers have since joined in independently, making repeated attempts to launder funds through THORChain and offshore casinos.
Most of the stolen Bitcoin remains frozen in attacker-controlled addresses and has not moved further.
Notably, the stolen funds carried an average dormancy period of 3.18 years, indicating the losses are concentrated among long-term self-custody holders rather than active traders or exchange users.
Galaxy is collecting victim reports and attacker-address data and sharing it with US law enforcement and industry participants as its investigation continues.
What Comes Next
Galaxy has cautioned that its loss estimate could rise again if new address patterns surface, and Coinkite has promised a formal technical review of the incident.
What this means for you: if you use a Coldcard, treat this as urgent regardless of how small your balance is, since the third wave shows attackers are now working through smaller wallets, and migrating to a freshly generated seed on updated firmware is the only way to remove the risk rather than simply updating the device.
If you use a different hardware wallet, this is still a useful prompt to confirm how your own device generates entropy for seed creation. Our wallets guide covers hardware wallet fundamentals and self-custody security practices in more depth.

