- Galaxy Research now tracks roughly $88.6 million stolen from approximately 4,585 Coldcard addresses across three attack waves.
- Galaxy’s Alex Thorn described the thefts as LLM-orchestrated, warning that every single-sig Coldcard address created after a March 2021 firmware flaw will eventually be drained.
- The breach has forced victims to reverse the “not your keys, not your coins” ethos by moving Bitcoin back to centralized exchanges for safety.
The ongoing exploit targeting Coldcard hardware wallets continues to escalate, with Galaxy Research now tracking roughly $88.6 million stolen from 4,585 addresses in three distinct waves.
Galaxy’s head of research Alex Thorn posted to X that the attack remains active and urged all users to move funds immediately. The flaw originated from a March 2021 firmware build error on Coinkite’s devices that generated seed phrases with insufficient randomness, leaving private keys guessable.
Thorn described the sweeps as deliberate and likely orchestrated with a large language model, warning that every single-sig Coldcard address created after that 2021 update will inevitably be emptied. The stolen coins had remained untouched for an average of 3.18 years, indicating long-term holders were targeted.
One victim, Canadian coach Jonathan Goodman, reported losing 18.25 BTC worth approximately $1.6 million Canadian on July 29, despite his keys sitting in a safety deposit box never connected to the internet. “Perhaps the hardest part about this is that I did everything right,” he wrote.
Consequently, the fallout has driven a panicked reversal of the industry’s standard “not your keys, not your coins” ethos. Affected users are now racing to move Bitcoin off self-custody and back onto centralized exchanges such as Coinbase or Binance for safekeeping.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
