Coldcard Hack Losses Remain Unclear as Estimates Range From 1,432 to 1,730+ BTC

 

Coldcard hack losses unclear 1432 to 1730 Bitcoin stolen CryptoQuant Galaxy TRM estimates

Aug 11, 2026 – More than a week after the Coldcard hardware wallet vulnerability was disclosed, the total scale of stolen Bitcoin remains uncertain. Blockchain analytics firms have arrived at different figures, reflecting the difficulty of measuring losses from self-custody wallets where there is no complete list of affected accounts.

Blockchain analytics platform CryptoQuant currently puts confirmed losses at 1,432 BTC. The firm takes a conservative approach, starting with public reports from victims — including wallet addresses or transaction IDs — and verifying those against known on-chain attack patterns before confirming them.

"Because the stolen Bitcoin belonged to individuals and not to a centralized entity, like an exchange, we can only confirm what each victim publicly discloses."
— Julio Moreno, Head of Research at CryptoQuant

 

Galaxy Research and TRM Labs Point to Higher Numbers

Galaxy Research and blockchain intelligence firm TRM Labs both say their analysis points to a higher toll, while distinguishing between losses directly confirmed by victims and funds attributed to the attack through on-chain patterns.

As of Tuesday, Galaxy put its high-confidence minimum at 1,730 BTC, with Galaxy's Alex Thorn saying the figure could still increase as more victim reports corroborate attack patterns. The firm's earlier potential estimate of 1,816 BTC, which appeared in some reports, was a potential figure rather than a confirmed loss total.

"We have directly confirmed 450+ BTC directly from victim reports, but their reports have helped identify other, as-yet-unknown victims in more than 730 total BTC. We are still withholding many more BTC we suspect but for which we lack sufficient corroboration."
— Alex Thorn, Galaxy Research

TRM Labs said its independent tracing lands in the same range as Galaxy, estimating that attackers drained about 1,816 BTC from more than 5,200 addresses across four waves. TRM's global head of policy Ari Redbord said that the estimate should be expected to keep moving upward before it stabilizes.

 

Why the Numbers Differ

The discrepancy comes down to methodology. CryptoQuant only counts losses that victims have publicly disclosed and that the firm can verify through on-chain patterns. Galaxy and TRM cast a wider net, using victim reports to identify attack patterns and then tracing additional addresses that match those patterns, even if the owners haven't come forward.

Moreno emphasized that the total will remain an estimate because investigators can only confirm what victims disclose:

"Knowing the total BTC stolen is difficult, and it will always be an estimation."
— Julio Moreno, CryptoQuant

 

The Exploit and Its Aftermath

The vulnerability stems from a March 2021 firmware integration error that, on affected devices, caused seed generation to use a deterministic software pseudorandom number generator instead of the hardware random number generator of the STM32 chip. On affected Mk3 seeds, effective entropy could fall to roughly 40 bits instead of the expected 128 bits, making private keys potentially brute-forceable.

The vulnerability affected seeds generated under specific firmware conditions across Coldcard models, with the Mk3 facing the most severe entropy reduction. Mk4, Mk5 and Q devices were also later identified as affected under certain pre-fix firmware conditions, although their affected seeds had higher effective entropy.

Coinkite released fixed firmware for the affected models — Mk3 version 4.2.0 or later, Mk4/Mk5 version 5.6.0 or later, and Coldcard Q version 1.5.0Q or later. Updating the firmware does not repair a seed that was already generated under vulnerable conditions, so affected users should follow Coinkite's migration guidance and generate a new seed after installing the fixed firmware.

 

The Bottom Line

As of now, the confirmed loss figure remains contested. CryptoQuant's 1,432 BTC represents a floor based on victim-disclosed losses, while Galaxy's 1,730 BTC high-confidence minimum includes additional funds identified through on-chain pattern analysis. The figures could rise as more victims come forward and investigators gain additional evidence linking addresses to the attack.

For affected users, the message is clear: if a wallet seed was generated on a vulnerable Coldcard device, the funds should be moved to a new seed generated on patched firmware — regardless of the exact loss figures.


CoinaiNews provides independent market analysis and coverage of cryptocurrency, technology, and financial markets. The information presented does not constitute financial advice.

 

Post a Comment

0 Comments