Galaxy Research has documented 1,596 Bitcoin stolen across confirmed attacks on Coldcard hardware wallets, with potential total losses reaching 2,055 BTC or over $130 million. The figure comes from three major incidents and 14 smaller breaches affecting roughly 7,300 different Bitcoin addresses. A fourth suspected attack remains under investigation.

The culprit is a flaw in Coldcard's random number generation mechanism. The vulnerability impacts specific firmware versions across Coldcard Mk3, Mk4, Mk5, and the newer Q model. Coinkite, the manufacturer, pushed out an urgent software update immediately after the discovery and urged users to patch devices right away.

Most Stolen Funds Still Sitting Untouched

Here's what stands out: approximately 90% of the stolen Bitcoin remains at the original addresses where it was taken. The attackers haven't begun moving it to exchanges or mixing services. That's unusual for theft on this scale and suggests either a pause in laundering operations or attackers waiting for market conditions to shift.

Galaxy Research has been coordinating with US federal investigators and major crypto exchanges to track the stolen assets and identify those behind the attacks. The team is monitoring blockchain movements closely.

Timeline and Evidence

The research shows strong indicators of a fourth attack using the same vulnerability, though full confirmation is pending. If included, total losses would hit the 2,055 BTC mark. The confirmed thefts happened across three separate major incidents with 14 additional smaller attacks documented.

For more details on the Coldcard breach impact, the investigation continues as law enforcement and exchange teams track the flow of assets.

This article is informational and does not constitute investment advice or financial guidance.