Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster
Summary
Beginning July 31, 2026, at least 15 distinct threat actors exploited a five-year-old firmware vulnerability in Coldcard hardware wallets to drain an estimated 1,596–2,055 BTC (approximately $100–130 million) from over 7,300 victim addresses. Galaxy Research identified each actor by behavioral fingerprints — labeling them Footprints A through O — and shared roughly 600 suspected attacker-controlled addresses with U.S. federal law enforcement, crypto exchanges, and compliance firms. As of August 4–5, 2026, approximately 90% of confirmed stolen funds remain dormant in identified on-chain addresses, with 100% of funds from the first three attack waves unmoved, suggesting actors are timing exchange-monitoring windows before attempting liquidation.
Connected Entities
1 entitiesTimeline(8 events)
2021-03-01
Coldcard firmware 4.0.0 released containing an integration error that routed seed generation to a software PRNG instead of the hardware RNG, introducing the vulnerability.
The Hacker News2026-07-31
Wave 1: Approximately 1,082.65 BTC swept from 1,196 addresses between 01:31 and 01:56 UTC in roughly 41 minutes. 562 BTC consolidated to address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
CoinDesk / The Hacker News2026-08-01
Wave 2 identified. Galaxy Research reports total losses reached approximately $75 million. Coinkite issues advisory urging users to move funds.
CryptoTimes2026-08-02
Wave 3 identified. Galaxy Research confirms losses have reached approximately $88.6 million across 4,585 addresses (1,367.05 BTC). Coinkite publishes official blog update confirming the vulnerability and emergency firmware patches.
CryptoTimes / Coinkite Blog2026-08-03
Wave 4 observed live. Approximately 388.9–448.7 BTC swept from 462–709 victim addresses within 2.5 hours. Galaxy Research puts total losses at approximately $114 million.
CryptoTimes2026-08-04
Galaxy Research confirms at least 15 distinct attacking entities (Footprints A through O), with confirmed losses of 1,596 BTC (~$100M+) and suspected total of 2,055 BTC (~$130M). Galaxy reports approximately 600 attacker addresses to U.S. federal law enforcement, exchanges, and compliance firms. 73 victims engaged directly with researchers.
CryptoTimes / CoinTelegraph / The Block2026-08-04
CoinDesk reports Coldcard urging all users to move funds as exploit remains active. Forbes, TechCrunch, and Fortune publish major coverage of the incident.
CoinDesk2026-08-05
On-chain messaging activity documented at primary Wave 1 consolidation address. At least one OP_RETURN message offering unsolicited money-laundering services identified. 90% of stolen BTC remains unmoved. No arrests or fund seizures announced.
CryptoTimesDecision Log
- #1publish⛓ pending8/5/2026, 11:06:39 PMhash: BMC3R4ePWtKWkpXfVaQWQ5VFtqy6a24L29kWbHeuoa8R
28 of 31 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/5/2026, 11:06:27 PM
last updated: 8/6/2026, 12:27:06 PM
avoid.net — verified advice for a post-truth world