Aug 11, 2026 – More than a week after the
Coldcard hardware wallet vulnerability was disclosed, the total scale of stolen
Bitcoin remains uncertain. Blockchain analytics firms have arrived at different
figures, reflecting the difficulty of measuring losses from self-custody
wallets where there is no complete list of affected accounts.
Blockchain analytics platform CryptoQuant currently
puts confirmed losses at 1,432 BTC. The firm takes a conservative
approach, starting with public reports from victims — including wallet
addresses or transaction IDs — and verifying those against known on-chain
attack patterns before confirming them.
"Because the stolen Bitcoin belonged to individuals
and not to a centralized entity, like an exchange, we can only confirm what
each victim publicly discloses."
— Julio Moreno, Head of Research at CryptoQuant
Galaxy Research and TRM Labs Point to Higher Numbers
Galaxy Research and blockchain intelligence
firm TRM Labs both say their analysis points to a higher toll,
while distinguishing between losses directly confirmed by victims and funds
attributed to the attack through on-chain patterns.
As of Tuesday, Galaxy put its high-confidence minimum
at 1,730 BTC, with Galaxy's Alex Thorn saying the figure could
still increase as more victim reports corroborate attack patterns. The firm's
earlier potential estimate of 1,816 BTC, which appeared in some reports, was a
potential figure rather than a confirmed loss total.
"We have directly confirmed 450+ BTC directly from
victim reports, but their reports have helped identify other, as-yet-unknown
victims in more than 730 total BTC. We are still withholding many more BTC we
suspect but for which we lack sufficient corroboration."
— Alex Thorn, Galaxy Research
TRM Labs said its independent tracing lands in the same
range as Galaxy, estimating that attackers drained about 1,816 BTC from
more than 5,200 addresses across four waves. TRM's global head of policy Ari
Redbord said that the estimate should be expected to keep moving upward before
it stabilizes.
Why the Numbers Differ
The discrepancy comes down to methodology. CryptoQuant only
counts losses that victims have publicly disclosed and that the firm can verify
through on-chain patterns. Galaxy and TRM cast a wider net, using victim
reports to identify attack patterns and then tracing additional addresses that
match those patterns, even if the owners haven't come forward.
Moreno emphasized that the total will remain an estimate
because investigators can only confirm what victims disclose:
"Knowing the total BTC stolen is difficult, and it
will always be an estimation."
— Julio Moreno, CryptoQuant
The Exploit and Its Aftermath
The vulnerability stems from a March 2021 firmware
integration error that, on affected devices, caused seed generation to use a
deterministic software pseudorandom number generator instead of the hardware
random number generator of the STM32 chip. On affected Mk3 seeds, effective
entropy could fall to roughly 40 bits instead of the expected 128 bits, making
private keys potentially brute-forceable.
The vulnerability affected seeds generated under specific
firmware conditions across Coldcard models, with the Mk3 facing the most severe
entropy reduction. Mk4, Mk5 and Q devices were also later identified as
affected under certain pre-fix firmware conditions, although their affected
seeds had higher effective entropy.
Coinkite released fixed firmware for the affected models —
Mk3 version 4.2.0 or later, Mk4/Mk5 version 5.6.0 or later, and Coldcard Q
version 1.5.0Q or later. Updating the firmware does not repair a seed that was
already generated under vulnerable conditions, so affected users should follow
Coinkite's migration guidance and generate a new seed after installing the
fixed firmware.
The Bottom Line
As of now, the confirmed loss figure remains contested.
CryptoQuant's 1,432 BTC represents a floor based on
victim-disclosed losses, while Galaxy's 1,730 BTC high-confidence
minimum includes additional funds identified through on-chain pattern analysis.
The figures could rise as more victims come forward and investigators gain
additional evidence linking addresses to the attack.
For affected users, the message is clear: if a wallet seed
was generated on a vulnerable Coldcard device, the funds should be moved to a
new seed generated on patched firmware — regardless of the exact loss figures.
CoinaiNews provides independent market analysis and
coverage of cryptocurrency, technology, and financial markets. The information
presented does not constitute financial advice.

0 Comments