Coldcard Exploit: 87% of $114M+ in Stolen Bitcoin Remains Unspent

AI Market Summary
Galaxy Research traced 1,789.28 BTC (~$114.7M at theft) from a Coldcard entropy/firmware randomness failure, with 87.3% still unmoved in attacker-controlled addresses. The large parked balances preserve strong on-chain traceability and increase the chance of interdiction if funds reach centralized venues, but ongoing mixing in later waves highlights persistent wallet-security and operational-risk overhang for Bitcoin holders.
Impact level
● Medium
Affected assets
BTC/USDT-0.52%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Most of the Bitcoin linked to the Coldcard exploit is still sitting idle, giving on-chain investigators an unusually clear look at attacker-held balances as they continue to map losses exceeding $114 million. Galaxy Research's Alex Thorn traced 1,789.28 BTC stolen from 8,865 addresses to the Coldcard-related thefts, worth about $114.7 million at the time (roughly $138.8 million at current prices). Of that amount, 1,561 BTC—about 87.3%—remains consolidated in attacker-controlled collection or holding addresses and has not been spent. Galaxy added that including medium-confidence clusters would lift the estimate to around 1,824 BTC, or approximately $140 million at the time of the thefts. Galaxy's dataset shows 8,865 affected addresses, with a median loss of 0.00152 BTC and a mean loss of 0.20184 BTC. The coins had often been dormant for years before being taken: median dormancy was 3.2 years, with a mean of 3.6 years. Victim submissions include 221 reports covering 790.72 BTC, representing 44.2% of the tracked total; within those reports, the median claimed loss was 1.04272 BTC and the mean was 3.57792 BTC, with median dormancy at 3.25 years. Movement has begun in later theft waves, and Galaxy said the attackers have used CoinJoin transactions, peel chains, and other mixing methods to complicate tracing. Coins associated with the first three identified waves, though, have not been moved or mixed, leaving investigators with clean on-chain records to monitor for any outbound activity. TRM Labs attributed the incident to a firmware-related randomness failure. A build-configuration error introduced in March 2021 caused impacted Coldcard devices to fall back to a weaker software random number generator instead of relying solely on hardware entropy. The reduced entropy can make private keys recoverable via brute force without physical access to the device. TRM Labs emphasized that installing patched firmware does not fix a seed that has already been compromised; affected users need to generate a new seed on secure hardware and move funds to addresses derived from that new seed. Galaxy Research said it is sharing confirmed attacker addresses with exchanges, compliance firms, and law enforcement to support identification efforts and potential freezes if the funds reach centralized platforms. With most large balances still parked and unmixed, investigators retain a meaningful tracing advantage, though mixing behavior in later waves is increasing complexity. The episode also adds to a broader wallet-security debate focused on the risks of weak randomness in seed generation. This summer included Coinspect's "Ill Bloom" finding, which cited poor randomness in certain software wallets and saw roughly $5 million moved from exposed wallets. Ledger Donjon also demonstrated a laser attack on a Tangem card that required physical access and expensive lab equipment. Separately, on-chain investigator ZachXBT publicly questioned whether hardware wallets are suitable for very large, mission-critical transactions, framing it as a personal assessment rather than new evidence of compromise. For users who created a wallet seed on an affected Coldcard device, the recommended remediation is to generate a fresh seed on secure hardware and sweep funds to new addresses; firmware updates alone are not sufficient. Standard best practices still apply: keep firmware updated, prefer hardware RNG where available, and consider splitting large holdings across multiple secure solutions. Investigators continue monitoring the 1,561 BTC that remains unmoved while expanding attribution to additional addresses and attack waves. The lack of movement could become pivotal if the attackers ultimately attempt to cash out through centralized services.