Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4SdRBx…MnB6Summary
Beginning July 31, 2026, at least 15 distinct threat actors exploited a five-year-old firmware vulnerability in Coldcard hardware wallets to drain an estimated 1,596–2,055 BTC (approximately $100–130 million) from over 7,300 victim addresses. Galaxy Research identified each actor by behavioral fingerprints — labeling them Footprints A through O — and shared roughly 600 suspected attacker-controlled addresses with U.S. federal law enforcement, crypto exchanges, and compliance firms. As of August 4–5, 2026, approximately 90% of confirmed stolen funds remain dormant in identified on-chain addresses, with 100% of funds from the first three attack waves unmoved, suggesting actors are timing exchange-monitoring windows before attempting liquidation.
Connected Entities
5 entities · 60 linked investigations- Ethereum→mentioned with→Bitcoin(60%)
- THORChain→mentioned with→Ethereum(70%)
- THORChain→mentioned with→Bitcoin(60%)
- Coinkite→mentioned with→Bitcoin(70%)
- Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster→mentioned with→Bitcoin(70%)
- Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster→mentioned with→Coinkite(70%)
- Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster→mentioned with→THORChain(65%)
- Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster→mentioned with→Ethereum(65%)
Community submissions
- Under reviewincriminatingWayback pending9/16/2026, 11:09:44 AM
“TRM Labs definitive forensic report: confirms multi-actor exploitation, 5,200+ victim addresses, largest hardware wallet hack in history; legal recovery track now being organized by Fieldfisher and WeirFoulds”
— avoid-scout
- Under reviewincriminatingWayback pending8/8/2026, 10:13:00 PM
“TechCrunch reporting from August 4 confirms 15+ independent attacker groups and total losses exceeding $130M — material escalation beyond prior evidence on file for this entity”
— avoid-scout
Timeline(8 events)
March 2021
Coldcard firmware 4.0.0 released containing an integration error that routed seed generation to a software PRNG instead of the hardware RNG, introducing the vulnerability.
The Hacker News31 July 2026
Wave 1: Approximately 1,082.65 BTC swept from 1,196 addresses between 01:31 and 01:56 UTC in roughly 41 minutes. 562 BTC consolidated to address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.
CoinDesk / The Hacker NewsAugust 2026
Wave 2 identified. Galaxy Research reports total losses reached approximately $75 million. Coinkite issues advisory urging users to move funds.
CryptoTimes2 August 2026
Wave 3 identified. Galaxy Research confirms losses have reached approximately $88.6 million across 4,585 addresses (1,367.05 BTC). Coinkite publishes official blog update confirming the vulnerability and emergency firmware patches.
CryptoTimes / Coinkite Blog3 August 2026
Wave 4 observed live. Approximately 388.9–448.7 BTC swept from 462–709 victim addresses within 2.5 hours. Galaxy Research puts total losses at approximately $114 million.
CryptoTimes4 August 2026
Galaxy Research confirms at least 15 distinct attacking entities (Footprints A through O), with confirmed losses of 1,596 BTC (~$100M+) and suspected total of 2,055 BTC (~$130M). Galaxy reports approximately 600 attacker addresses to U.S. federal law enforcement, exchanges, and compliance firms. 73 victims engaged directly with researchers.
CryptoTimes / CoinTelegraph / The Block4 August 2026
CoinDesk reports Coldcard urging all users to move funds as exploit remains active. Forbes, TechCrunch, and Fortune publish major coverage of the incident.
CoinDesk5 August 2026
On-chain messaging activity documented at primary Wave 1 consolidation address. At least one OP_RETURN message offering unsolicited money-laundering services identified. 90% of stolen BTC remains unmoved. No arrests or fund seizures announced.
CryptoTimesDecision Log
- hash: HzZiGMMK5mnAbxdpwQEXTSdMcr2RXACzmk5qd7Lw63b4
- hash: DWSosSzNwDyQ7hanzT98qjFTSELqqHioQ81Nqgy12Wgw
- hash: BkqciycvuoUCqyf39hPneLNa7HctohgSB3aMNSCjKMbg
- hash: BMC3R4ePWtKWkpXfVaQWQ5VFtqy6a24L29kWbHeuoa8R
This investigation is cryptographically anchored to the Solana blockchain (4 events). 30 of 31 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/5/2026, 11:06:27 PM
last updated: 8/25/2026, 11:08:41 PM
4 viewsavoid.net — verified advice for a post-truth world