Bitcoin Coldcard Losses Reach 1,367 BTC After Third Wave

Three suspected Coldcard attack waves drained 1,367.05 BTC, about $88.6 million, while Coinkite urges Bitcoin users to migrate weak seeds.

(09:16 AM UTC)
6 min read
Updated
AI SummaryAI
  • Three suspected Coldcard attack waves drained 1,367.05 BTC, about $88.6 million, from 4,585 addresses.
  • The first July 30 sweep moved 1,082.65 BTC from 1,196 addresses in roughly 41 minutes.
  • Sub-1 BTC transfers reached 39,600 BTC in one day, the highest since November 2022.
  • Jonathan Goodman said he lost $1.6 million in Bitcoin from an offline Coldcard setup.
k7rq2fdm

On-chain analysis of the Coldcard firmware flaw shows Bitcoin losses have expanded to 1,367.05 BTC, about $88.6 million, across 4,585 addresses after three suspected attack waves. The first sweep began early on July 30 and moved 1,082.65 BTC from 1,196 addresses in roughly 41 minutes, using a 30 satoshi-per-virtual-byte fee and no change outputs, traits that made the cluster easier to trace. A second wave on July 31 took 76.16 BTC from 1,478 addresses, while a later batch removed 207.7294 BTC from 1,912 addresses. The latest total supersedes an earlier $70.2 million estimate and remains an observed figure, not a final audit. Coinkite has said integration errors prevented the hardware random-number generator from contributing properly to seed creation, and fixed firmware only prevents new weak seeds. Users must generate and fund a fresh seed. The episode has become a stress test for self-custody, and our Bitcoin hub is tracking the migration guidance.

Smaller Bitcoin transfers have reached levels last seen during the FTX collapse, signalling that many holders are moving funds away from potentially exposed addresses. Sub-1 BTC transactions climbed to 39,600 BTC in a single day, the highest daily total since November 2022 and only about 300 BTC below the 39,900 BTC recorded on Nov. 16, 2022, when FTX was failing. The on-chain surge coincided with researchers continuing to identify new victim and attacker addresses, and the suspected campaign remained active. The moment has reopened a bear-market-era argument about whether individuals should rely on self-custody or regulated custodians. Some security practitioners argue distributed self-custody gave users time to react, because potentially far more BTC was protected by independent wallets than was identified as stolen. Others counter that exchange-traded funds and professional custodians reduce technical risk for users who cannot manage firmware, seeds and address verification. The pattern suggests risk mitigation, not panic selling, because the transfers were fragmented and below 1 BTC. The same caution applies to any altcoin held through self-custody.

The Coldcard vulnerability has also intensified a custody-security debate among industry figures after entrepreneur Jonathan Goodman said he lost $1.6 million in Bitcoin from an offline setup. Goodman described keys held on a Coldcard device that had never connected to the internet and stored in a safe-deposit box, a configuration many users regard as conservative. BlockTower Capital founder Ari Paul argued that no custody method is risk-free: platform custody introduces counterparty and legal risk, while individual custody introduces hardware, software and operational risk. Paul also said legal institutions in developed markets can currently offer more reliable property protection than cryptographic control alone. ShapeShift founder Erik Voorhees pushed back, saying the incident does not prove crypto assets cannot be stored safely, though he agreed no model is perfect. The debate is less about price or all-time-high expectations than about control, moving the discussion away from absolute security toward measurable trade-offs. That framing matters for both institutions and individuals.

Individual accounts are giving the technical failure a human scale, with one user saying more than 3 BTC, worth nearly $200,000, disappeared after years of regular saving. The user said funds were withdrawn from an exchange in 2022 and moved to a Coldcard, followed by weekly purchases of about $250 and occasional extra deposits, with the balance rarely checked. The loss underscores why Coinkite’s July 31 emergency firmware update is not a complete remedy. The company has warned that updating firmware can correct future seed generation, but it cannot add entropy to an already-created recovery phrase. Coinkite’s advisory tells users to verify device versions, create a completely new seed, test the receiving address with a small transaction and then migrate remaining funds. The underlying flaw traces to a March 2021 code path that could bypass the hardware random-number generator, leaving some keys with far less search space than intended. For a Bitcoin holder following the standard cold-storage playbook, the failure is a reminder that legacy seeds need active migration.

Galaxy Research's on-chain forensics reveal that the third attack wave differs from the first two across nearly every measurable behavioral dimension. Where earlier sweeps funneled funds through a small set of shared collection addresses using P2WPKH outputs and targeted one victim per transaction, the latest batch employed unique destination addresses per victim, consolidated roughly 6.37 victim inputs per transaction, and held proceeds in P2WSH wallets while scanning only default derivation paths. The firm says these shifts could reflect a single operator retooling to complicate tracing, or a separate actor exploiting the same vulnerable key pool after public disclosure of the flaw. Galaxy Research is confident each wave was directed by one operator but stops short of linking all three to a common entity. Notably, none of the approximately 1,366.39 BTC now sitting in attacker-controlled addresses has been spent on-chain.

Bloomberg Intelligence senior ETF analyst Eric Balchunas said on Aug. 2 that the Coldcard failure bolsters the argument for regulated U.S. spot Bitcoin ETFs, which remove seed-management duties from individual investors while providing institutional custody at lower fees than private alternatives. Balchunas pointed out that Coinkite employs roughly five people according to PitchBook and LinkedIn data, a headcount he called a red flag given the sums its devices are expected to safeguard. He acknowledged that ETF holders give up direct ownership, round-the-clock network access and on-chain transaction capability, making the wrapper suitable mainly for those seeking price exposure alone. No verified fund-flow data yet connects the incident to new ETF demand, as U.S. markets were closed during his weekend posts and BlackRock's latest official figures predate his remarks.

(as of 00:41 UTC) COINOTAG's proprietary 42-indicator composite S/R scoring engine shows Bitcoin trading at $63,406, caught between the $63,997 resistance rated 64/100 by Ichimoku Kijun, R2, BB Middle and SMA 20 confluence and nearby support at $63,376 scoring 89/100 from Fibo 0.214, S1, POC and SMA 50. The strongest overhead barrier beyond that is $66,978 at 63/100, driven by EMA 100, Donchian Upper, Keltner Upper and LVN signals, while a secondary support shelf at $61,893 scores 79/100 from Keltner Lower, Fibo 0.114, HVN and Supertrend. Derivatives positioning is mildly crowded long: funding is 0.0040%, open interest is $12.84 billion and the long/short account ratio is 1.96. Fear & Greed reads 28/100, showing fear rather than euphoria. A sustained break above $63,997 would open a move toward $66,978, but losing $63,376 would confirm the bearish MACD and sideways trend; a break below $61,893 would invalidate any near-term recovery thesis.

Michael Roberts

Michael Roberts

COINOTAG author

View all posts
AI-AssistedCrypto Research Analyst·Michael Roberts is a crypto research analyst focused on blockchain technology, decentralized finance (DeFi), and Web3 ecosystem developments.

AI-generated, AI-reviewed, under COINOTAG editorial oversight.