Security Hub

Galaxy Research: 1,778 BTC Stolen in Coldcard Exploit

Published: Aug 15, 2026By Aleksandar Dukic

Key Analysis

Galaxy Research says over 1,778 BTC has been drained in the Coldcard hardware wallet exploit across three waves and 33+ attacker footprints, with no attacks confirmed after August.

Galaxy Research: 1,778 BTC Stolen in Coldcard Exploit

Listen To This Article

Galaxy Research: 1,778 BTC Stolen in Coldcard Exploit

4m 26s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

Galaxy Research has put a hard number on one of the year's larger self-custody thefts. In an August 15 update relayed by CoinMarketCap, the firm said more than 1,778 BTC has been stolen through the Coldcard hardware wallet exploit, spread across three major waves and tied to over 33 distinct attacker footprints on-chain. At Bitcoin's price of roughly $63,010 as of August 15, 2026, that haul is worth about $112 million.

The update matters because it moves the story from scattered victim reports to a mapped, quantified campaign. Galaxy's researchers are treating the thefts as a coordinated series rather than isolated one-off compromises, and they note no confirmed attacks after August. That timeline gives affected holders a clearer picture of when the exposure window opened and, tentatively, when it closed.

The scale behind the number

1,778 BTC is not a rounding error in the hardware wallet world. Coldcard, built by Coinkite, markets itself to the security-first end of the Bitcoin market: air-gapped signing, no USB data connection required, and a physical device most buyers choose precisely to avoid this outcome. A loss of this size against that product is the kind of event that forces the whole self-custody segment to re-examine assumptions.

The three-wave structure is the detail worth sitting with. Coordinated waves suggest the attackers had a repeatable method rather than a lucky one-time break. The 33-plus attacker footprints Galaxy counted point to either multiple actors working the same weakness or a single group deliberately fragmenting funds across wallets to complicate tracing. Either reading is consistent with a planned operation, not opportunistic theft.

The seed phrase, not the chip

Hardware wallet losses rarely come from someone physically cracking the device. The far more common failure is upstream, in how the seed phrase was generated, stored, or entered. Earlier reporting on this same campaign found that thieves consolidated most of the stolen Bitcoin into a small handful of destination wallets, behavior that lines up with attackers who already held the keys and simply swept balances on their own schedule.

That distinction changes the lesson. A device can be flawless and a wallet can still be drained if the entropy behind the seed was weak, if the recovery phrase touched an internet-connected screen, or if a tampered supply chain delivered a pre-seeded device. Holders who bought hardware wallets secondhand, accepted a "pre-configured" unit, or ever typed their 24 words into a phone or laptop sit in the highest-risk group regardless of which brand is on the box.

For anyone weighing where their coins live, this is a reminder that self-custody options remove counterparty risk but hand you full responsibility for key hygiene. Custodial products carry the opposite trade: an exchange or issuer holds the keys, which means no seed for you to leak but real exposure if that provider fails. Neither model is safe by default. Each just relocates the risk.

Practical steps for Coldcard holders

Holders who suspect exposure should assume the seed, not the hardware, is the compromised element. Rotating to a freshly generated wallet with entropy created on the device itself, then moving funds to those new addresses, is the standard response. Continuing to receive into an address derived from a possibly-compromised seed keeps the door open.

Buyers should also treat provenance as part of security. A hardware wallet is only trustworthy if it arrives sealed, direct from the manufacturer, and is initialized by the owner with a seed no one else has seen. Convenience shortcuts, a friend's spare device, a marketplace deal, a unit that came already set up, are exactly the vectors a campaign like this feeds on.

Galaxy's finding that no attacks are confirmed after August offers a measure of relief, but "no confirmed attacks" is not the same as "resolved." Until Coinkite or independent researchers publish a definitive root cause, the prudent stance for any holder with doubts is to migrate to a clean seed rather than wait for a final verdict.

Overview

Galaxy Research quantified the Coldcard hardware wallet exploit at more than 1,778 BTC, about $112 million at August 15 prices, taken across three waves and 33-plus attacker footprints, with no attacks confirmed after August. The pattern points to a coordinated campaign exploiting seed-phrase weaknesses rather than a break in the physical device. Coldcard users who bought secondhand or pre-configured units, or who ever exposed their recovery phrase, should treat their seed as compromised and migrate funds to a freshly generated wallet. The episode is a blunt reminder that self-custody removes counterparty risk but puts key hygiene entirely on the holder.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.