More than $88 million worth of Bitcoin has been swept from thousands of wallets in what looks like a third wave of attacks linked to a Coldcard hardware wallet vulnerability. The latest activity shows a shift in tactics, complicating the tracing of stolen funds and raising fresh alarms for security watchers.

Three Waves Drain Over 1,300 BTC

According to blockchain analytics firm Galaxy Research, the theft involves 1,367 BTC stolen from 4,585 addresses in three distinct waves between July 30 and August 1, 2026. The first wave alone snatched roughly 1,083 BTC from 1,195 wallets in less than an hour. The second wave took a smaller haul, about 76 BTC from 1,478 addresses the following day.

The third wave marked a notable change. Instead of consolidating funds into a few addresses, attackers dispersed the stolen Bitcoin into nearly 300 separate P2WSH vaults. These vaults can obscure spending conditions until the coins are moved, making it significantly harder for analysts to track the stolen assets. Galaxy suspects either the original attacker altered their strategy after earlier thefts became public or a new group exploited the same vulnerability.

Exchange Deposits and Dormant Coins Signal Bigger Trends

Adding to the concern, Binance and other exchanges saw net deposits of 11,163 BTC on July 31, coinciding with the timing of the theft waves. This influx could suggest some of the stolen Bitcoin is being funneled into exchanges, possibly to launder or liquidate the assets.

Galaxy linked the theft to a known security flaw in a Coinkite Coldcard firmware version released in March 2021. The affected coins mostly came from addresses inactive for about 3.5 years, consistent with long-term cold storage wallets. This detail highlights the risk that even dormant holdings are vulnerable if hardware wallet vulnerabilities are exploited.

The ongoing inflows to exchanges tie into a broader pattern of crypto hacks, such as the recent surge in July when losses reached $210 million largely due to known security gaps. The Coldcard incident adds a fresh dimension by targeting hardware wallet users who typically rely on offline storage to secure assets.

This article is for informational purposes and does not constitute financial advice.