
Galaxy Research raises Coldcard loss estimate to $88.6M
Galaxy Research has raised its estimate of Bitcoin drained from addresses linked to the Coldcard firmware flaw to 1,367.05 BTC, worth about $88.6 million, on Aug. 1. The updated figure replaces the $70.2 million estimate reported after its initial onchain mapping. Galaxy described the total as its “estimated observed size,” leaving open the possibility that further transactions could be found, and the company has not proved that every address came from a vulnerable Coldcard seed.
Key figures at a glance
- First wave (July 30): 1,082.65 BTC from 1,196 addresses
- Second wave (July 31): 76.16 BTC from 1,478 addresses
- Third wave: 207.7294 BTC from 1,912 addresses
- Combined observed total: 1,367.05 BTC from 4,585 addresses
What the three attack waves looked like
Galaxy’s first mapped wave occurred between 1:10:20 a.m. and 1:51:26 a.m. UTC on July 30, draining 1,082.65 BTC from 1,196 addresses across blocks 960,183 through 960,191. The transactions appeared about 30 hours before Coinkite issued its initial public advisory. The first wave used the same 30 satoshis per virtual byte fee and transactions without change outputs, traits that helped researchers identify the related movements onchain. Galaxy warned that later attacks might use different patterns, making the complete loss harder to measure.
A second sweep and a different third wave
A second wave on July 31 drained 76.16 BTC from another 1,478 addresses. Galaxy later identified a third wave that removed 207.7294 BTC from 1,912 addresses. The first two waves shared collector addresses, destination types and derivation-path behavior, and occurred about 27 hours apart. Those similarities suggested one operator may have conducted both sweeps, although the blockchain cannot establish the attacker’s identity.
The third wave behaved differently: funds from each victim moved to separate pay-to-witness-script-hash destinations, while several victims were grouped into each sweep transaction. The activity also checked only the default derivation path. Galaxy said it was confident each wave represented one operator, but would not claim that one attacker controlled all three. Therefore, descriptions of a single hacker remain an inference rather than a confirmed fact. Galaxy called the third group “what we suspect are hacks of Coldcard-generated addresses,” reflecting the limits of onchain attribution.
Firmware integration error and affected models
Coinkite said a series of firmware integration errors prevented the intended hardware random-number generator from contributing properly to seed creation. A MicroPython software fallback supplied predictable output after a March 2021 code change. Engineers at Block described the same random-number-generator path and said active exploitation was underway.
Coinkite estimated about 40 bits of effective search space for affected Mk2 and Mk3 seeds. Later Mk4, Q and Mk5 models included extra secure-element entropy, but the company estimated roughly 72 bits rather than the intended 128 bits. These figures remain technical estimates and may change as testing continues.
Which firmware versions are affected?
- Mk2 and Mk3: firmware 4.0.1 through 4.1.9
- Mk4 and Mk5: seeds created before standard version 5.6.0
- Q: seeds created before version 1.5.0Q
- Separate fixed Edge releases are available
Migration required: updates alone are not enough
Coinkite released hotfixes for every affected model and said it takes “full accountability” for the bug. However, installing new firmware only corrects future seed generation; it cannot add entropy to a recovery phrase that already exists.
The guidance tells users to install the fixed firmware, generate a completely new seed, verify its backup and receiving address, and send a small test transaction before moving the remaining balance. Users should keep the previous backup until the migration is confirmed.
Coinkite said seeds created with at least 50 fair, independent and private dice rolls are not considered exposed by this issue alone. A strong, unique BIP-39 passphrase adds another barrier, but the company still advises migration. Short, reused or predictable passphrases may not provide adequate protection. However, AnchorWatch’s Rob Hamilton offered a contrary view, and a later technical review examined how the firmware build error weakened Coldcard seeds for more than five years.
Coinkite’s investigation remains open, and the company has promised a formal technical review. Galaxy may also revise the observed loss again if new address patterns emerge. Until those reviews are complete, $88.6 million is the latest public estimate, not a final confirmed total. No verified Bitcoin price reaction has been attributed to the Coldcard incident so far.






