Technology & Security

Researchers Track $138M Coldcard Theft as Attackers Hold 87% of Stolen Bitcoin

Galaxy Research has traced 1,789 BTC stolen in the Coldcard hardware wallet exploit, revealing that 87.3% of the funds remain untouched in attacker-controlled addresses despite some movement through CoinJoin and peel chains.

Researchers Track $138M Coldcard Theft as Attackers Hold 87% of Stolen Bitcoin
Over 87% of Bitcoin stolen in the Coldcard wallet exploit remains unmoved in attacker wallets. Photo: Pexels

More than 87% of the Bitcoin stolen during the widespread Coldcard hardware wallet exploit remains unmoved, according to ongoing onchain tracking data released by Galaxy Research. Head of Research Alex Thorn confirmed that 1,561 BTC, out of 1,789.28 BTC traced to the breach, remains static across attacker-controlled holding addresses. While the stolen assets were valued at $114.7 million at the time of the exploit, current market prices value the unmoved holdings at approximately $138.8 million.

The unspent balance across the initial three attack waves provides blockchain investigators with a clear, traceable record of the primary wallet clusters. Galaxy has shared identified attacker addresses with centralized cryptocurrency exchanges, compliance providers, and law enforcement agencies to facilitate potential freezing orders should the funds eventually interact with regulated platforms.

Onchain Distribution and Victim Metrics

Galaxy’s investigation combines address-level chain analysis with verified victim reports across 8,865 compromised addresses. The metrics reveal a stark contrast between overall network averages and self-reported individual losses.

Overall Network Dataset (8,865 addresses):

  • Median Loss: 0.00152 BTC
  • Average Loss: 0.20184 BTC
  • Asset Dormancy: Dormant for a median of 3.2 years (average 3.6 years) prior to theft.

Verified Victim Submissions (221 reports covering 790.72 BTC):

  • Median Loss: 1.04272 BTC
  • Average Loss: 3.57792 BTC
  • Asset Dormancy: Dormant for a median of 3.25 years (average 2.99 years) prior to theft.

Thorn noted that accounting for additional medium-confidence addresses currently under evaluation would bring total estimated losses to roughly 1,824 BTC, representing approximately $140 million at the time of execution.

Root Cause, Obfuscation, and Hardware Security Implications

The exploit stems from a critical software build configuration error introduced in a March 2021 firmware update for Coldcard devices, as previously identified by TRM Labs. The error caused affected hardware wallets to bypass dual hardware secure elements and fall back on a weaker software random number generator during seed phrase creation. The resulting reduction in entropy allowed attackers to recover private keys via offchain brute-force computation without requiring physical access to the devices.

While funds from the earliest attack vectors remain completely dormant, attackers have begun moving stolen assets from later exploit waves. Observed obfuscation techniques include mixing stolen funds with unrelated transaction inputs to obscure origin trails and iteratively transferring small increments from primary balances through long series of newly created addresses.

Security researchers emphasize that updating a Coldcard device to fixed firmware does not remediate an existing wallet generated under compromised entropy. Affected users must generate an entirely new seed phrase on a secure device and migrate all funds to newly derived addresses to prevent further unauthorized drain.

Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

DeFi & FinTech, News, Technology & Security

More from CoinScreamer