Fact-check findings
What an automated fact-checker found when it re-read Coldcard / Coinkite — August 2026 Multi-Actor Attacker Cluster against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
disputed
7 claimsThe reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.
- #1[disputed][awaiting moderator]in the summary
“Beginning July 31, 2026”
reviewerWave 1 of the theft began on July 31, 2026Multiple independent sources (Protos timeline, an independent on-chain technical writeup) place Wave 1 at July 30, 2026, not July 31. The cited CoinDesk article is dated July 31 because that is when the news broke, one day after the sweep.Proposed correction (not yet applied)Beginning July 30, 2026 - #6[disputed][awaiting moderator]in section: Attacker Cluster Identification and Scale
“led by Head of Research Alex Thorn”
reviewerGalaxy Research is led by Head of Research Alex ThornMinor but verifiable title inaccuracy; his official title includes 'Firmwide.'Proposed correction (not yet applied)led by Head of Firmwide Research Alex Thorn - #11[disputed][awaiting moderator]in section: Stolen Funds: Confirmed Amounts and Wave Breakdown
“Wave 1, occurring July 31, 2026 between 01:31 and 01:56 UTC, swept 1,082.65 BTC from approximately 1,196 addresses in roughly 41 minutes”
reviewerWave 1 swept 1,082.65 BTC from ~1,196 addresses between 01:31 and 01:56 UTC on July 31, 2026, in ~41 minutesThe stated window (01:31-01:56) is only 25 minutes, internally inconsistent with the sentence's own '41 minutes' claim, and does not match independent on-chain timelines, which place the sweep at 01:10-01:51 UTC on July 30.Proposed correction (not yet applied)Wave 1, occurring July 30, 2026 between 01:10 and 01:51 UTC, swept 1,082.65 BTC from approximately 1,196 addresses in roughly 41 minutes - #18[disputed][awaiting moderator]in section: Exploitation Method and Open-Market Entry
“originated in Coldcard firmware version 4.0.0, released March 1, 2021”
reviewerThe vulnerability originated in Coldcard firmware version 4.0.0, released March 1, 2021The page conflates the internal code-commit date with the public firmware release date; the same error recurs in the timeline entry's date_original field.Proposed correction (not yet applied)originated in Coldcard firmware version 4.0.0, released March 17, 2021 - #32[disputed][awaiting moderator]in the timeline
“2021-03-01”
reviewerFirmware 4.0.0 was released on 2021-03-01, introducing the vulnerabilitySame underlying error as the sections[4] finding; the stored date_original field should reflect the public release date, not the commit date.Proposed correction (not yet applied)2021-03-17 - #33[disputed][awaiting moderator]in the timeline
“2026-07-31”
reviewerWave 1 occurred on 2026-07-31Timeline date field should match the actual sweep date (July 30), not the date the news broke (July 31).Proposed correction (not yet applied)2026-07-30 - #34[disputed][awaiting moderator]in the timeline
“between 01:31 and 01:56 UTC in roughly 41 minutes”
reviewerWave 1 occurred between 01:31 and 01:56 UTCThe stated 01:31-01:56 window is only 25 minutes, internally inconsistent with the event text's own '41 minutes' and with independent on-chain analysis.Proposed correction (not yet applied)between 01:10 and 01:51 UTC in roughly 41 minutes
unverifiable
1 claimNo source the reviewer could reach confirms or contradicts the claim.
- #17[unverifiable][awaiting moderator]in section: Transaction Fingerprinting and On-Chain Attribution Methodology
“Additional cluster addresses include bc1qx76cae2706qd5q576feh7xq8rfcsjpf2htfhe3 (approximately 398.48 BTC from 491 inputs) and bc1q8jy96fe5lf8vfugydnte3cguk92gpev7kwtp3q (approximately 89.62 BTC from 204 inputs).”
reviewerAdditional cluster addresses moved ~398.48 BTC (491 inputs) and ~89.62 BTC (204 inputs)Plausible and consistent with the page's overall reporting on wallet consolidation, but the specific per-address BTC and input counts could not be independently verified with the tools available.
stale
4 claimsThe claim was accurate when written but events since have overtaken it.
- #2[stale][awaiting moderator]in the summary
“at least 15 distinct threat actors”
reviewerAt least 15 distinct threat actors have exploited the vulnerabilityThe 15-attacker figure was accurate as of August 4, 2026 but was superseded within two weeks by Galaxy Research's own revised count of over 33 footprints; the page presents the number without a time-bound qualifier in the summary.Proposed correction (not yet applied)at least 33 distinct threat actors - #5[stale][awaiting moderator]in the summary
“with 100% of funds from the first three attack waves unmoved”
reviewerAs of Aug 4-5, 2026, ~90% of stolen funds remain dormant, with 100% of Wave 1-3 funds unmovedThe 100%/90% figures were accurate on August 4-5, 2026, the date the page cites, but have since been superseded by Galaxy Research's own follow-up reporting showing active cash-out from the Wave 3 cluster.Proposed correction (not yet applied)though by September 2026 Galaxy Research reported dormancy had fallen to approximately 82%, with the Wave 3 cluster actively cashing out via THORChain and CoinJoin transactions - #7[stale][awaiting moderator]in section: Attacker Cluster Identification and Scale
“identified at least 15 distinct attacking entities through on-chain behavioral fingerprinting”
reviewerGalaxy Research identified at least 15 distinct attacking entities through on-chain behavioral fingerprintingSame underlying staleness as the summary's 15-attacker figure.Proposed correction (not yet applied)identified at least 33 distinct attacking entities through on-chain behavioral fingerprinting - #27[stale][awaiting moderator]in section: Dormant Fund Status and Liquidation Risk
“Furthermore, 100% of funds from the first three confirmed attack waves have not moved from their identified attacker wallet destinations.”
reviewerAs of Aug 4-5, 2026, ~90% of stolen BTC remains unmoved, 100% of Wave 1-3 funds unmovedAccurate as of the page's stated date but materially superseded by subsequent Galaxy Research reporting.Proposed correction (not yet applied)Furthermore, as of early August 2026, 100% of funds from the first three confirmed attack waves had not moved from their identified attacker wallet destinations; by September 2026, Galaxy Research reported the Wave 3 cluster had begun actively cashing out via THORChain and CoinJoin transactions, lowering overall dormancy across the exploit to approximately 82%.
link rot
1 claimA cited source no longer resolves or no longer says what the page attributes to it.
- #35[link rot][awaiting moderator]in the cited sources
“https://web.archive.org/web/20260805232004/https://alexablockchain.com/nchain-signs-agreement-with-nagex-to-develop-blockchain-based-carbon-exchange-platform/”
reviewerAlexaBlockchain source archive snapshot for the Coldcard theft articleThe live source URL itself is fine and was confirmed to match the page's cited content; only the archive_url snapshot is mismatched and points to an unrelated article.Proposed correction (not yet applied)http://web.archive.org/web/20260805231958/https://alexablockchain.com/coldcard-bitcoin-theft-tops-102m-as-investigators-track-at-least-15-attacker-patterns/
partially supported
1 claimThe cited evidence supports part of the claim but not all of it.
- #21[partially supported][awaiting moderator]in section: Exploitation Method and Open-Market Entry
“Dragonfly managing partner Haseeb Qureshi stated that AI models reportedly rediscovered the vulnerability in under 20 minutes, though crypto analytics firm Tokenomist disputed the source of that claim as deriving from a pseudonymous Reddit user who scanned code after the vulnerability was already public.”
reviewerHaseeb Qureshi said AI reportedly rediscovered the vulnerability in under 20 minutes; Tokenomist disputed the source as a pseudonymous Reddit user who scanned public codeThe page conflates two distinct claims from its own cited article: Qureshi's 20-minute figure (from a claimed blind GLM-5.2 test) and a separate, faster 2-minute viral claim that Tokenomist specifically traced to an after-the-fact Reddit demonstration. Presenting Tokenomist's rebuttal as directed at Qureshi's claim overstates the connection between the two.
confirmed
21 claimsThe cited evidence supports the claim as written.
- #3[confirmed][no action needed]in the summary
“drain an estimated 1,596–2,055 BTC (approximately $100–130 million) from over 7,300 victim addresses”
reviewerThe attack drained an estimated 1,596-2,055 BTC (~$100-130M) from over 7,300 victim addressesFigures are consistent across multiple independent outlets reporting on the same Galaxy Research data as of August 4, 2026. - #4[confirmed][no action needed]in the summary
“shared roughly 600 suspected attacker-controlled addresses with U.S. federal law enforcement, crypto exchanges, and compliance firms”
reviewerGalaxy Research shared roughly 600 suspected attacker addresses with US federal law enforcement, exchanges, and compliance firmsCorroborated by contemporaneous reporting. - #8[confirmed][no action needed]in section: Attacker Cluster Identification and Scale
“running from Footprint A through Footprint O as of August 4, 2026”
reviewerFootprints were catalogued A through O as of August 4, 2026Unlike the unqualified '15 distinct threat actors' claims elsewhere, this sentence correctly scopes the count to a specific date. - #9[confirmed][no action needed]in section: Attacker Cluster Identification and Scale
“The fifteenth footprint (O) was identified only after a victim reported a loss of under 1 BTC, which allowed Galaxy to trace a previously uncatalogued attacker who had moved approximately 12 BTC across 126 addresses.”
reviewerFootprint O was identified after a victim reported a loss of under 1 BTC, tracing an attacker who moved ~12 BTC across 126 addressesFigures independently corroborated. - #10[confirmed][no action needed]in section: Attacker Cluster Identification and Scale
“Galaxy cautioned that the 15 clusters do not necessarily represent 15 individuals — some addresses may be controlled by the same person or group, and additional attackers may remain unidentified.”
reviewerGalaxy cautioned that the 15 clusters may not represent 15 individualsConsistent with multiple analytics firms' cautious framing of attribution. - #12[confirmed][no action needed]in section: Stolen Funds: Confirmed Amounts and Wave Breakdown
“Waves 2 and 3 brought the confirmed total to 1,367.05 BTC across 4,585 addresses.”
reviewerWaves 2 and 3 brought the confirmed total to 1,367.05 BTC across 4,585 addressesMatches independent reporting. - #13[confirmed][no action needed]in section: Stolen Funds: Confirmed Amounts and Wave Breakdown
“Wave 4 was observed live on August 3, 2026, sweeping an estimated 388.9–448.7 BTC across 462–709 victim addresses within approximately 2.5 hours.”
reviewerWave 4 swept an estimated 388.9-448.7 BTC across 462-709 addresses within ~2.5 hours, observed live August 3, 2026Confirmed by the cited source. - #14[confirmed][no action needed]in section: Stolen Funds: Confirmed Amounts and Wave Breakdown
“Loss estimates escalated from approximately $38 million at initial discovery, to $88.6 million by the weekend, to over $100 million confirmed by August 4, 2026.”
reviewerLoss estimates escalated from ~$38M to $88.6M to over $100M by August 4, 2026Escalation sequence matches the dated headlines in the page's own source list. - #15[confirmed][no action needed]in section: Transaction Fingerprinting and On-Chain Attribution Methodology
“Galaxy Research measured Wave 1's sweep rate at approximately 13.8 transfers per block against a pre-incident baseline of 0.3 per block, which Thorn described as 'the fingerprint of an automated pipeline chewing through a pre-computed list of vulnerable keys against a live mempool.'”
reviewerWave 1's sweep rate was ~13.8 transfers per block vs a 0.3/block baseline; Thorn called it 'the fingerprint of an automated pipeline...'Quote and statistics independently corroborated. - #16[confirmed][no action needed]in section: Transaction Fingerprinting and On-Chain Attribution Methodology
“Galaxy also noted that the sweeps were assessed as 'probably orchestrated with a large language model,' though this characterization was not independently confirmed.”
reviewerGalaxy assessed the sweeps as 'probably orchestrated with a large language model'Quote and appropriate hedging both confirmed. - #19[confirmed][no action needed]in section: Exploitation Method and Open-Market Entry
“This reduced effective entropy to approximately 40 bits on Mk2/Mk3 devices and approximately 72 bits on Mk4/Mk5/Q devices, versus the 128-bit standard for a 12-word BIP-39 seed.”
reviewerEntropy fell to ~40 bits on Mk2/Mk3 and ~72 bits on Mk4/Mk5/Q, vs the 128-bit BIP-39 standardFigures for Mk3 and Mk4/Mk5/Q independently confirmed; Mk2 is grouped with Mk3 in Coinkite's own fix versioning, consistent with the page's grouping. - #20[confirmed][no action needed]in section: Exploitation Method and Open-Market Entry
“Affected firmware versions include Mk2/Mk3 versions 4.0.0 through 4.1.9, Mk4/Mk5 versions prior to 5.6.0, and Q model versions prior to 1.5.0Q. Wallets generated using the dice-roll option with 50 or more manual rolls are not considered affected.”
reviewerAffected versions: Mk2/Mk3 4.0.0-4.1.9, Mk4/Mk5 prior to 5.6.0, Q prior to 1.5.0Q; dice-roll with 50+ rolls unaffectedConfirmed against Coinkite's own official security-status page. - #22[confirmed][no action needed]in section: Law Enforcement Cooperation and Exchange Monitoring
“Galaxy Research supplied approximately 600 suspected attacker-controlled addresses to U.S. federal law enforcement, major cryptocurrency exchanges, compliance firms, cyber investigators, and the Security Alliance (SEAL), a non-profit providing 24/7 incident response coordination for the crypto industry.”
reviewer~600 addresses shared with US federal law enforcement, exchanges, compliance firms, cyber investigators, and SEAL; 73 victims engaged; no arrests as of Aug 5Consistent with contemporaneous reporting and SEAL's own self-description. - #23[confirmed][no action needed]in section: Law Enforcement Cooperation and Exchange Monitoring
“Coinkite stated that its legal team 'will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible.'”
reviewerCoinkite's legal team will coordinate with law enforcement across multiple jurisdictionsDirect quote verified against the primary source. - #24[confirmed][no action needed]in section: Law Enforcement Cooperation and Exchange Monitoring
“No public arrests, indictments, or fund seizures had been announced as of August 5, 2026.”
reviewerNo public arrests, indictments, or fund seizures had been announced as of August 5, 2026Claim is explicitly time-bound and remains accurate for the date stated; no arrests had been publicly confirmed as of this review (Sept 2026) either. - #25[confirmed][no action needed]in section: Law Enforcement Cooperation and Exchange Monitoring
“one such embedded message constituted an alleged money-laundering solicitation offering a 10% fee for KYC bypass services”
reviewerOP_RETURN messaging at the Wave 1 consolidation address included a money-laundering solicitation offering a 10% fee for KYC bypassConsistent with the cited outlet's reporting. - #26[confirmed][no action needed]in section: Alleged Laundering Activity and Cross-Chain Movement
“including a platform identified as 'Duel,' where funds were reportedly withdrawn before account-level freezes could be applied”
reviewerFunds deposited to gambling platform 'Duel' were withdrawn before account-level freezes could be appliedDirectly supported by the page's own cited source. - #28[confirmed][no action needed]in section: Dormant Fund Status and Liquidation Risk
“The average targeted wallet had been dormant for approximately 3.18 years before being swept, indicating the victim population consisted disproportionately of long-term Bitcoin holders.”
reviewerThe average targeted wallet had been dormant for approximately 3.18 years before being sweptFigure independently corroborated. - #29[confirmed][no action needed]in section: Dormant Fund Status and Liquidation Risk
“A subset of attackers has reportedly begun cross-chain conversion, with some BTC alleged to have been swapped to Ethereum via THORChain and routed through Tornado Cash, though the scale of these movements relative to total stolen funds is not independently confirmed at the time of this investigation.”
reviewerSome BTC was allegedly swapped to ETH via THORChain and routed through Tornado Cash; scale not independently confirmedAppropriately hedged claim, corroborated in substance and in its acknowledgment of unconfirmed scale. - #30[confirmed][no action needed]in section: Attribution Gaps and Unknown Actor Risk
“Investigators have not linked the incident to any known state-sponsored threat group, including those previously associated with North Korea or Russia, though such attribution has not been publicly ruled out.”
reviewerNo confirmed off-chain identities attributed to any footprint as of Aug 5, 2026; no link to known state-sponsored groupsNo public reporting found linking the incident to a state-sponsored group; claim accurately reflects the state of public attribution. - #31[confirmed][no action needed]in section: Attribution Gaps and Unknown Actor Risk
“Coinkite's emergency firmware update does not remediate seeds already generated under the vulnerable firmware, meaning funds in legacy wallets remain at risk until moved.”
reviewerCoinkite's emergency firmware update does not remediate seeds already generated under vulnerable firmwareConfirmed against Coinkite's own official guidance.