Wire
23:42ZTASNIMNEWSIsraeli foreign minister says Gaza will not be rebuilt until Hamas is disarmed23:42ZSCMPNEWSChina Courts Europe with AI Models to Counter US Tech Dominance23:41ZSCMPNEWSJellyfish force shutdown of 3 reactors at French nuclear plant23:38ZSCMPNEWSChina says US attempted to purchase super magnet with 40% higher performance23:37ZINTELSLAVAExplosions reported in Sevastopol, Crimea23:35ZSCMPNEWSSearch underway for missing cruise passenger off Hong Kong mega bridge23:34ZSCMPNEWSHong Kong opens trade office in Malaysia, bridging Greater Bay Area: minister23:33ZSCMPNEWSChinese husband builds world's largest hollyhock garden inspired by wife's childhood memory
  • S&P 500 ETF 0.01%
  • Nasdaq 0.60%
  • Nasdaq 100 0.33%
  • Dow ETF 0.01%
Terminal ↗
← The MonexusCrypto

Coldcard-linked Bitcoin thefts climb past $88M as Galaxy tracks a third sweep wave

Galaxy Research now traces 1,367 BTC across 4,585 addresses to a single suspected attacker, as Coinkite's Mk3 seed-generation warning collides with a still-growing drain.

Orange Monexus News graphic displays the word "CRYPTO" with a placeholder notice reading "No photograph on file."
Orange Monexus News graphic displays the word "CRYPTO" with a placeholder notice reading "No photograph on file." Monexus News

At 16:59 UTC on 2 August 2026, The Hacker News relayed a Galaxy Research update raising the running estimate of Bitcoin lost in the Coldcard-linked wallet drain to $88.6 million, after two additional sweep waves pushed the suspected total to 1,367.05 BTC across 4,585 addresses. The escalation follows a second wave Galaxy flagged the previous afternoon and a third the firm says is still in progress. A week earlier, the publicly discussed figure was a single unexplained $38 million drain.

The story now reads less like a one-off theft and more like a slow-motion compromise of an entire cohort of addresses that share a common origin in Coinkite's Mk3 device, with private keys apparently reconstructed offline rather than lifted from the devices themselves. Monexus analysis: the mechanism, if confirmed by Coinkite or independent researchers, would change the threat model for every user who ever generated a seed on the affected firmware.

What the numbers say

Galaxy's first published tally, dated 1 August and reported by Cointelegraph at 09:23 UTC, identified 1,196 addresses that lost 1,082.65 BTC. Cointelegraph's headline framed the dollar value of that loss at $70 million. By 18:31 UTC on 1 August, a second wave had pushed losses to 1,158.81 BTC across 2,673 addresses. By 16:59 UTC on 2 August, with the third wave underway, the running total had reached 1,367.05 BTC across 4,585 addresses, with dollar-denominated losses of approximately $88.6 million.

The pace is what stands out. Two named sweep waves in roughly 33 hours, each sweeping more than a thousand addresses, with the third wave still active. CoinDesk's reporting on the first wave, published 1 August at 05:55 UTC, described an attacker who recreated likely private keys offline, swept more than 1,000 BTC from nearly 1,200 wallets and continued searching without ever accessing the devices. The pattern, in Monexus's assessment, is consistent with offline key recovery from a known weakness, not with a remote exploit.

The Mk3 warning underneath

The theft story sits on top of a quieter advisory from Coinkite, the maker of the Coldcard line. On 31 July at 02:50 UTC, CryptoBriefing's Telegram channel relayed a Coinkite warning that a security flaw in the Mk3 model may put user Bitcoin at risk. Cointelegraph's own report that morning, at 02:38 UTC, said Coinkite had urged Coldcard Mk3 users to migrate funds after identifying a potential seed-generation risk, with Bitcoin security experts separately examining the then-$38 million drain.

The framing matters. The cited material does not record Coinkite publicly confirming that the Mk3 seed-generation flaw is the vector the attacker used, and the available source items do not specify whether Coinkite has named a root cause or issued a firmware fix. What the cited reporting establishes is a temporal coincidence: a vendor warning about seed-generation risk, and an offline attacker who appears able to regenerate keys from a known starting point.

Why an offline attacker changes the threat model

A hardware wallet's central promise is that the private key never leaves a tamper-resistant device. An offline attacker who can reproduce those keys without touching the device breaks that promise at the architectural level. The CoinDesk account describes an adversary who worked from likely-key inputs, not from a compromised device or a phished seed phrase. Monexus analysis: if the seed-generation routine on the affected firmware produced keys from a search space smaller than its entropy suggested, an attacker with the right inputs and sufficient compute could reconstruct private keys at scale and sweep any address that had not yet moved its funds.

That is why the per-wave address counts matter more than the headline dollar figure. Each sweep wave is a batch of address-by-address draining across a shared cohort. Galaxy's third-wave identification on 2 August at 01:22 UTC, relayed through DarkWebInformer's X account, suggests the attacker still has unspotted addresses in the cohort to drain and is methodically working through them.

What remains contested

Two things are not yet pinned down in the cited reporting. First, attribution: Galaxy uses the word "suspected" throughout, and the cited posts describe the events as "suspected hacks of Coldcard-generated addresses" rather than confirmed exploits of a specific firmware version. Second, the dollar valuation, which moves with the spot price of Bitcoin and which Galaxy appears to recalculate as new sweeps are confirmed.

A third question is whether every drained address in the cohort actually traces back to a Coldcard Mk3. The reporting frames the thefts as Coldcard-linked, not Coldcard-confirmed, and the available source items do not specify the verification method Galaxy used to attribute addresses to the device.

The next data point to watch is whether Coinkite publishes a root-cause statement and a firmware fix, and whether the third sweep wave completes or stalls. If it completes, the address count and dollar figure will keep rising. If it stalls without a vendor explanation, the question of which cohort of users was actually exposed will remain open.

Desk note: Monexus is reporting the Galaxy Research estimates as running tallies rather than final figures, and is treating the Coinkite advisory as a related but not-yet-causally-linked warning. Where the cited material uses "suspected" or "likely", this article has preserved that hedge.

Wire provenance

This editorial synthesis draws on the following public wire/social posts:

  • https://cointelegraph.com/news/coldcard-bitcoin-loss-estimate-70-million-galaxy-analysis
  • https://www.coindesk.com/tech/2026/08/01/how-bitcoin-cold-wallets-lost-usd70-million-in-an-attack-that-never-touched-the-devices
  • https://t.me/CryptoBriefing/18497
  • https://cointelegraph.com/news/coldcard-mk3-warning-594-btc-sweep
  • https://t.me/thehackernews/9687
  • https://thehackernews.com/2026/08/coldcard-hardware-wallet-flaw-linked-to.html
  • http://nitter.perennialte.ch/glxyresearch/status/2083623500183421043
  • https://x.com/DarkWebInformer/status/2083725013862015340
  • http://nitter.perennialte.ch/glxyresearch/status/2083560940469981591
  • https://x.com/DarkWebInformer/status/2083621745525694885
© 2026 Monexus Media · AI-native reporting from public-source material