Breaking Crypto Whales Accumulate AAVE, UNI, and MOVR Heading Into October
Crypto Market News

Coldcard Hacker’s Second Wave Pushes Galaxy Research’s Tracked Total to 1,158.81 BTC

By Mr Whale · August 31, 2026 · 3 min read
Share: X FB TG

July 30: the entropy flaw starts being exploited

The Coldcard saga began with a firmware change dating back to March 2021, which caused some affected hardware wallets to fall back to an inadequate source of entropy when generating wallet seeds — making those seeds mathematically predictable to anyone who knew what to look for. Attackers began systematically recreating vulnerable seeds and sweeping the resulting wallets starting from the early morning of July 30, and coin680 covered the first wave of that exploitation in late August, including reporting that pointed to the original thief potentially being identifiable to the FBI, and Coldcard’s own response forcing physical dice rolls before generating any new seed.

A second wave, tracked separately

Galaxy Research, which has been monitoring the exploit’s on-chain footprint since it surfaced, has now identified a second, distinct wave of sweeps that it attributes to the same attacker behind the original theft. In an update to its tracking thread, the firm said it is now following a combined total of 1,158.81 BTC stolen across 2,673 addresses from the two waves, with the funds held unspent across seven attacker-controlled addresses. The two waves are technically distinguishable in the data: Galaxy noted the first wave used a fixed transaction fee of 30 sat/vbyte, while the second wave mostly used either 10 sat/vbyte or 50 sat/vbyte, a fingerprint researchers used to attribute the second sweep to the same operator without relying on address reuse alone.

Why the money hasn’t moved

What stands out to Galaxy’s analysts isn’t just the size of the combined haul but its stillness. All 1,158.81 BTC remains sitting untouched across the seven attacker addresses, something the firm calls unusual for a theft of this scale — most operators holding tens of millions of dollars in stolen crypto move at least part of it quickly, either to launder it or cash out before exchanges and investigators can react. Galaxy’s read is that the attacker is either deliberately waiting out scrutiny or genuinely lacks a laundering path large enough to handle a sum this visible without drawing attention. The firm says it is now monitoring all seven addresses on every new block, meaning any future movement of funds should be caught in near real time.

What this update changes

For Coldcard users, the practical guidance hasn’t shifted: the vulnerability lies in seed generation on specific historical firmware, not in a design flaw that spreads to unaffected devices, and Coldcard’s dice-roll requirement for new seeds is aimed at closing that specific gap going forward. What this update does change is the scale of confirmed damage attributable to a single attacker, and it puts a harder number on how much of the stolen total remains fully traceable and unlaundered — a detail that matters both for potential recovery efforts and for understanding how large a single actor’s haul from this flaw actually became.

Hardware wallet security depends on both device design and how a user generates and stores a seed; this article is not financial or security advice, and Coldcard users with pre-fix devices should consult the manufacturer’s own guidance directly. For a broader primer on wallet security fundamentals, see coin680’s Bitcoin Academy.


Share: X FB TG
Written by Mr Whale

Mr Whale has been active in the crypto market since 2020 and leads content and research at Coin680. More about our editorial team →

Get the Coin680 Daily Brief

Bitcoin news, market moves, and Academy lessons -- straight to your inbox, no spam.

Leave a Comment