FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.6T -1.5%24h Vol $88.8B -2.5%Fear & Greed 69/100Alts Index 29/100
BTC.D 58.5% -0.1%Stable.D 10.0% +0.1%ETH.D 11.4% -0.1%Others.D 20.1% +0.1%
BR$0.5368+74.14%ZCAT$0.1237+41.96%AI$0.3128+13.43%PONS$0.6293+12.83%CAP$0.0634+11.59%龙虾$0.1577+11.38%XCN$0.00441453+10.6%NPC$0.0230+10.51%MINA$0.0864+6.52%UNI$6.680+6.03%
LSK$0.3449-39.5%BTW$0.6128-15.12%FIL$0.8728-12.67%STONK$0.2056-11.54%UAI$0.4453-9.92%B$0.2035-9.62%ZRO$0.9394-9.04%IOTA$0.0414-7.55%ICP$2.557-6.91%QTUM$0.8907-6.73%
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      Galaxy Traces $114.7M in Stolen BTC from Coldcard Exploit

      Galaxy Research has mapped 1,789.28 BTC, worth $114.7 million, stolen across 8,865 addresses in the ongoing Coldcard hardware wallet exploit, with 87.3% of the funds, roughly 1,561 BTC, still sitting in attacker-controlled addresses. Alex Thorn, Head of Research at Galaxy, published the updated tally on 25 August 2026, noting that no Bitcoin from the first three attack waves has been moved or laundered since the initial sweep in late July.

      Four Attack Waves Since Late July

      The exploit targets a firmware vulnerability introduced in March 2021 that compromised the entropy used to generate private keys on Coldcard devices. Galaxy Research identified four distinct attack waves, and the first wave on 30 July 2026 drained 1,082.65 BTC from 1,196 addresses in a 41-minute window, with every sweep paying an identical 30.0 sat/vB fee. Subsequent waves on 31 July, 2 August, and 3 August added a further 706.63 BTC from the remaining affected addresses.Galaxy's analysis of 221 victim reports covering 790.72 BTC, or 44.2% of total losses, found a median loss of 1.04272 BTC per report. The affected addresses had an average dormancy period of 3.18 years before the funds were swept, indicating the stolen Bitcoin was held in long-term cold storage by holders who believed their keys were secure.

      Recovery Prospects Hinge on Unmoved Funds

      "The funds remain in attacker-controlled collection or holding addresses, including all Bitcoin stolen during the first three attack waves," Thorn posted on X. He described the sweeps as "deliberate and programmatic" and speculated they were "probably orchestrated with a large language model." Galaxy has flagged approximately 600 suspected attacker addresses to federal investigators and compliance firms, and victim transaction details have aided the on-chain mapping effort.Thorn also warned that every single-signature Coldcard address created after March 2021 remains at risk. He urged holders to move funds immediately to an exchange account or a fresh self-custody address not generated on a Coldcard device. Galaxy later reported that at least 15 different attackers appear to be exploiting the same vulnerability.

      Self-Custody Tested at Scale

      The Coldcard exploit is the largest hardware wallet exploit on record, according to TRM Labs. Previous hardware wallet incidents, such as the Ledger supply-chain scare in 2023, targeted the software delivery pipeline rather than the cryptographic seed itself.One victim, Jonathan Goodman, told Decrypt he lost 18.25 BTC in seven minutes on the evening of 29 July local time, in the sweep Galaxy dates to 30 July, despite following all recommended security practices. "Perhaps the hardest part about this is that I did everything right," Goodman said.The fact that 87% of the stolen Bitcoin remains unmoved suggests one of two things: the attacker is waiting for enforcement attention to fade before attempting to liquidate, or the compliance pressure from Galaxy's federal referrals is constraining movement. The answer will likely emerge in the coming weeks as investigators and on-chain analysts continue to monitor the flagged addresses.

      Source: FinanceFeeds
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud