BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Markets

Galaxy Says Coldcard Bitcoin Thefts Topped $100M Across 3 Confirmed Attack Waves

Galaxy says confirmed Coldcard-related bitcoin thefts have topped $100 million, spread across three separate attack waves, marking an escalation in one of the year's most closely watched self

AnonymousCryptoCompass newsroom
August 4, 2026
4 min read
NEWS
Galaxy Says Coldcard Bitcoin Thefts Topped $100M Across 3 Confirmed Attack Waves
CryptoCompass editorial visual for markets coverage.

Galaxy says confirmed Coldcard-related bitcoin thefts have topped $100 million, spread across three separate attack waves, marking an escalation in one of the year's most closely watched self-custody security incidents.

KEY TAKEAWAYS

  • Galaxy estimates confirmed Coldcard-linked bitcoin thefts have exceeded $100 million.
  • The losses are attributed to three confirmed attack waves rather than a single event.
  • The figure is Galaxy's estimate of confirmed cases and does not capture any broader suspected losses.

What Galaxy reported about Coldcard bitcoin thefts

Galaxy's research arm now puts confirmed bitcoin thefts tied to the Coldcard hardware wallet above $100 million, according to reporting on the firm's findings. The estimate covers cases Galaxy describes as confirmed, grouped into three distinct attack waves. For related coverage, see Hashdex to Shut Bitcoin ETF After More Than Two Years.

That figure marks a sharp increase from Galaxy's earlier work, which had lifted the Coldcard loss estimate to $70 million as more affected wallets were traced. The revised total reflects confirmed thefts only, a distinction Galaxy draws to separate verified cases from any wider pool of suspected losses that remain unquantified. For related coverage, see Strategy Overhauls Its Bitcoin Metrics: What the New Reporting Means.

For bitcoin holders, the framing matters because Coldcard is a widely used cold-storage device marketed for self-custody. A confirmed nine-figure loss concentrated on a single hardware line raises questions about how the compromises occurred and whether other users remain exposed. For related coverage, see Bitcoin Holds Near $66,300 as Chips Rally, Yen Slides.

How the three confirmed attack waves unfolded

Galaxy groups the confirmed thefts into three waves rather than treating them as one continuous exploit, according to the reporting on its analysis. The brief does not specify precise dates, ordering, or the attacker methods behind each individual wave.

One thread connecting the incidents involves seed generation. Coldcard maker Coinkite has published a warning tied to Mk3 seed generation, the process by which a wallet's recovery phrase is created. Weakness in how a seed is generated can let an attacker reconstruct the keys protecting funds.

What remains unspecified is how each of the three waves maps to specific methods, timing, or attacker groups. Those mechanics are not detailed in the available evidence and should not be inferred beyond what Galaxy and Coinkite have stated.

What the report means for Coldcard users and bitcoin self-custody

The incident has already shown up in market behavior. CoinDesk reported that, unlike the FTX collapse, the exploit prompted some investors to send bitcoin back to exchanges, framing it around an $88 million Coldcard exploit. That reaction inverts the usual self-custody narrative, in which holders move coins off exchanges after a failure.

Galaxy has also moved beyond analysis, launching a $5 million bitcoin security fund connected to the episode. For current or prospective Coldcard users, the practical takeaway centers on the seed generation warning: users relying on potentially affected devices should follow Coinkite's guidance on verifying or regenerating their wallets.

The distinction between device risk and user operational security is important here. The confirmed losses appear tied to how keys were generated on the device, not to individual phishing or careless key handling, which points responsibility toward the hardware process rather than user error alone.

The scale is what makes the report significant. A confirmed total above nine figures, concentrated on one hardware wallet line and split across three separate waves, places this among the more consequential self-custody security events documented this year.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

Read original article on coinwy.comRead also :