Skip to main content
AVOID.NET

Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster

avoid.net/coldcard-coinkite-august-2026-multi-actor-attacker-cluster0/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4SdRBx…MnB6

Summary

Beginning July 31, 2026, at least 15 distinct threat actors exploited a five-year-old firmware vulnerability in Coldcard hardware wallets to drain an estimated 1,596–2,055 BTC (approximately $100–130 million) from over 7,300 victim addresses. Galaxy Research identified each actor by behavioral fingerprints — labeling them Footprints A through O — and shared roughly 600 suspected attacker-controlled addresses with U.S. federal law enforcement, crypto exchanges, and compliance firms. As of August 4–5, 2026, approximately 90% of confirmed stolen funds remain dormant in identified on-chain addresses, with 100% of funds from the first three attack waves unmoved, suggesting actors are timing exchange-monitoring windows before attempting liquidation.

Connected Entities

5 entities · 60 linked investigations
Organizations
Tokens
CoinkiteBitcoin62Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster
Relationships
  • Ethereummentioned withBitcoin(60%)
  • THORChainmentioned withEthereum(70%)
  • THORChainmentioned withBitcoin(60%)
  • Coinkitementioned withBitcoin(70%)
  • Coldcard / Coinkite — August 2026 Multi-Actor Attacker Clustermentioned withBitcoin(70%)
  • Coldcard / Coinkite — August 2026 Multi-Actor Attacker Clustermentioned withCoinkite(70%)
  • Coldcard / Coinkite — August 2026 Multi-Actor Attacker Clustermentioned withTHORChain(65%)
  • Coldcard / Coinkite — August 2026 Multi-Actor Attacker Clustermentioned withEthereum(65%)
Have evidence about Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster?
0
Accepted
2
Under review
0
Rejected / revoked

Community submissions

Timeline(8 events)

March 2021

Coldcard firmware 4.0.0 released containing an integration error that routed seed generation to a software PRNG instead of the hardware RNG, introducing the vulnerability.

The Hacker News

31 July 2026

Wave 1: Approximately 1,082.65 BTC swept from 1,196 addresses between 01:31 and 01:56 UTC in roughly 41 minutes. 562 BTC consolidated to address bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r.

CoinDesk / The Hacker News

August 2026

Wave 2 identified. Galaxy Research reports total losses reached approximately $75 million. Coinkite issues advisory urging users to move funds.

CryptoTimes

2 August 2026

Wave 3 identified. Galaxy Research confirms losses have reached approximately $88.6 million across 4,585 addresses (1,367.05 BTC). Coinkite publishes official blog update confirming the vulnerability and emergency firmware patches.

CryptoTimes / Coinkite Blog

3 August 2026

Wave 4 observed live. Approximately 388.9–448.7 BTC swept from 462–709 victim addresses within 2.5 hours. Galaxy Research puts total losses at approximately $114 million.

CryptoTimes

4 August 2026

Galaxy Research confirms at least 15 distinct attacking entities (Footprints A through O), with confirmed losses of 1,596 BTC (~$100M+) and suspected total of 2,055 BTC (~$130M). Galaxy reports approximately 600 attacker addresses to U.S. federal law enforcement, exchanges, and compliance firms. 73 victims engaged directly with researchers.

CryptoTimes / CoinTelegraph / The Block

4 August 2026

CoinDesk reports Coldcard urging all users to move funds as exploit remains active. Forbes, TechCrunch, and Fortune publish major coverage of the incident.

CoinDesk

5 August 2026

On-chain messaging activity documented at primary Wave 1 consolidation address. At least one OP_RETURN message offering unsolicited money-laundering services identified. 90% of stolen BTC remains unmoved. No arrests or fund seizures announced.

CryptoTimes
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (4 events). 30 of 31 cited source URLs have an Internet Archive snapshot.

Fact-checked 2026-09-0735 claims checked12 corrections pending0 applied⛓ anchoredSee findings →

model: claude-sonnet-4-6

generated: 8/5/2026, 11:06:27 PM

last updated: 8/25/2026, 11:08:41 PM

4 views

avoid.net — verified advice for a post-truth world