Coldcard Hacker’s Second Wave Pushes Galaxy Research’s Tracked Total to 1,158.81 BTC

July 30: the entropy flaw starts being exploited
The Coldcard saga began with a firmware change dating back to March 2021, which caused some affected hardware wallets to fall back to an inadequate source of entropy when generating wallet seeds — making those seeds mathematically predictable to anyone who knew what to look for. Attackers began systematically recreating vulnerable seeds and sweeping the resulting wallets starting from the early morning of July 30, and coin680 covered the first wave of that exploitation in late August, including reporting that pointed to the original thief potentially being identifiable to the FBI, and Coldcard’s own response forcing physical dice rolls before generating any new seed.
A second wave, tracked separately
Galaxy Research, which has been monitoring the exploit’s on-chain footprint since it surfaced, has now identified a second, distinct wave of sweeps that it attributes to the same attacker behind the original theft. In an update to its tracking thread, the firm said it is now following a combined total of 1,158.81 BTC stolen across 2,673 addresses from the two waves, with the funds held unspent across seven attacker-controlled addresses. The two waves are technically distinguishable in the data: Galaxy noted the first wave used a fixed transaction fee of 30 sat/vbyte, while the second wave mostly used either 10 sat/vbyte or 50 sat/vbyte, a fingerprint researchers used to attribute the second sweep to the same operator without relying on address reuse alone.
Why the money hasn’t moved
What stands out to Galaxy’s analysts isn’t just the size of the combined haul but its stillness. All 1,158.81 BTC remains sitting untouched across the seven attacker addresses, something the firm calls unusual for a theft of this scale — most operators holding tens of millions of dollars in stolen crypto move at least part of it quickly, either to launder it or cash out before exchanges and investigators can react. Galaxy’s read is that the attacker is either deliberately waiting out scrutiny or genuinely lacks a laundering path large enough to handle a sum this visible without drawing attention. The firm says it is now monitoring all seven addresses on every new block, meaning any future movement of funds should be caught in near real time.
What this update changes
For Coldcard users, the practical guidance hasn’t shifted: the vulnerability lies in seed generation on specific historical firmware, not in a design flaw that spreads to unaffected devices, and Coldcard’s dice-roll requirement for new seeds is aimed at closing that specific gap going forward. What this update does change is the scale of confirmed damage attributable to a single attacker, and it puts a harder number on how much of the stolen total remains fully traceable and unlaundered — a detail that matters both for potential recovery efforts and for understanding how large a single actor’s haul from this flaw actually became.
Hardware wallet security depends on both device design and how a user generates and stores a seed; this article is not financial or security advice, and Coldcard users with pre-fix devices should consult the manufacturer’s own guidance directly. For a broader primer on wallet security fundamentals, see coin680’s Bitcoin Academy.
