Losses tied to a years-old firmware flaw in Coinkite's Coldcard hardware wallets have climbed to roughly $88.6 million, according to new figures from Galaxy Research, as a fresh wave of thefts continues to drain vulnerable wallets. The latest tranche alone accounted for 207.73 BTC, part of a total of about 1,367 BTC stolen across 4,585 affected addresses since the campaign began.
The root cause traces back to a March 2021 firmware error on Coldcard devices that generated seed phrases with insufficient randomness, leaving private keys guessable by anyone capable of replicating the flawed generation process. Galaxy Research analyst Alex Thorn said the pattern of thefts appears "deliberate and programmatic," suggesting the attackers may be using large language model orchestration to systematically identify and drain exposed wallets.
Dormant Funds, Systematic Draining
Victim funds sat dormant for an average of 3.18 years before being swept, according to Galaxy's analysis, suggesting many holders had no idea their wallets were compromised until the coins were already gone. Investigators have flagged roughly 600 suspected attacker addresses so far, though the stolen funds have largely remained parked without further movement, a pattern that can complicate tracing efforts.
Galaxy's research also delivered a stark warning for anyone still holding funds in an affected device: all single-signature Coldcard addresses created after March 2021 will "eventually be drained" unless holders move their funds to newly generated, unaffected wallets.
A Personal Toll for Victims
The theft's most recent confirmed incident, dated July 29, added to a growing list of individual victims. Canadian coach Jonathan Goodman reported losing 18.25 BTC, worth close to $1.6 million CAD, describing the experience bluntly: "Perhaps the hardest part about this is that I did everything right."
"Perhaps the hardest part about this is that I did everything right."
As previously reported, the scale of the drain has already fueled arguments from some analysts that custody risk from self-hosted hardware wallets strengthens the case for regulated, ETF-based Bitcoin exposure instead. With losses still climbing and Galaxy warning that more affected wallets remain exposed, the incident is shaping up to be one of the more consequential hardware wallet security failures in Bitcoin's history.