Skip to main content
Sign in

Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster

avoid.net/coldcard-coinkite-august-2026-multi-actor-attacker-cluster0/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

Beginning July 31, 2026, at least 15 distinct threat actors exploited a five-year-old firmware vulnerability in Coldcard hardware wallets to drain an estimated 1,596–2,055 BTC (approximately $100–130 million) from over 7,300 victim addresses. Galaxy Research identified each actor by behavioral fingerprints — labeling them Footprints A through O — and shared roughly 600 suspected attacker-controlled addresses with U.S. federal law enforcement, crypto exchanges, and compliance firms. As of August 4–5, 2026, approximately 90% of confirmed stolen funds remain dormant in identified on-chain addresses, with 100% of funds from the first three attack waves unmoved, suggesting actors are timing exchange-monitoring windows before attempting liquidation.

Connected Entities

1 entities
Tokens
Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster
Relationships
    Have evidence about Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster?

    Timeline(8 events)

    2021-03-01

    Coldcard firmware 4.0.0 released containing an integration error that routed seed generation to a software PRNG instead of the hardware RNG, introducing the vulnerability.

    The Hacker News

    2026-07-31

    Wave 1: Approximately 1,082.65 BTC swept from 1,196 addresses between 01:31 and 01:56 UTC in roughly 41 minutes. 562 BTC consolidated to address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.

    CoinDesk / The Hacker News

    2026-08-01

    Wave 2 identified. Galaxy Research reports total losses reached approximately $75 million. Coinkite issues advisory urging users to move funds.

    CryptoTimes

    2026-08-02

    Wave 3 identified. Galaxy Research confirms losses have reached approximately $88.6 million across 4,585 addresses (1,367.05 BTC). Coinkite publishes official blog update confirming the vulnerability and emergency firmware patches.

    CryptoTimes / Coinkite Blog

    2026-08-03

    Wave 4 observed live. Approximately 388.9–448.7 BTC swept from 462–709 victim addresses within 2.5 hours. Galaxy Research puts total losses at approximately $114 million.

    CryptoTimes

    2026-08-04

    Galaxy Research confirms at least 15 distinct attacking entities (Footprints A through O), with confirmed losses of 1,596 BTC (~$100M+) and suspected total of 2,055 BTC (~$130M). Galaxy reports approximately 600 attacker addresses to U.S. federal law enforcement, exchanges, and compliance firms. 73 victims engaged directly with researchers.

    CryptoTimes / CoinTelegraph / The Block

    2026-08-04

    CoinDesk reports Coldcard urging all users to move funds as exploit remains active. Forbes, TechCrunch, and Fortune publish major coverage of the incident.

    CoinDesk

    2026-08-05

    On-chain messaging activity documented at primary Wave 1 consolidation address. At least one OP_RETURN message offering unsolicited money-laundering services identified. 90% of stolen BTC remains unmoved. No arrests or fund seizures announced.

    CryptoTimes
    Provenance & Audit Trail
    28 Wayback Archives

    Decision Log

    • #1publish⛓ pending8/5/2026, 11:06:39 PM
      hash: BMC3R4ePWtKWkpXfVaQWQ5VFtqy6a24L29kWbHeuoa8R

    28 of 31 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/5/2026, 11:06:27 PM

    last updated: 8/6/2026, 12:27:06 PM

    avoid.net — verified advice for a post-truth world