A sustained exploitation of Coldcard Bitcoin wallets has continued to unfold, with observers updating estimates of losses as the activity expands to more addresses and larger totals. Galaxy Research has reported that a third wave of thefts tied to Coldcard-generated keys has pushed the tally higher, counting approximately 1,367 BTC across about 4,585 addresses at the latest assessment. The unfolding pattern suggests the attacker is broadening the scope of targets and refining on-chain collection methods as the campaign persists.
The incidents center on weaknesses believed to lie in Coldcard-generated keys, with the attacker reportedly exploiting those vulnerabilities to drain balances from a broad set of wallets. The evolving nature of the operation has included adjustments to how funds are consolidated on the blockchain, indicating an ongoing attempt to optimize the theft and reduce traces as the scene grows. As more wallets are compromised, the total value moved on-chain has risen toward the threshold reported by researchers, drawing attention from blockchain analytics firms tracking the case.
Unlike some high-profile crypto-adverse events in the past, observers note a notable shift in investor behavior linked to this Coldcard breach. A portion of the affected holders appears to be transferring Bitcoin to exchanges in an effort to secure assets, a move described by analysts as a safety-oriented response. In practice, this means funds are being moved off cold storage and into exchange wallets or custody facilities, a pattern that contrasts with what followed the FTX collapse in late 2022, when many investors retrenched differently amid market turmoil.
The latest findings from Galaxy Research emphasize that the third wave has targeted smaller balances, signaling a change in how the attacker is structuring the campaign. By broadening the sweep to more modest holdings, the attacker can increase the number of compromised addresses while maintaining a steady inflow of funds to on-chain collection points. The research team also notes that the attacker has altered on-chain collection mechanics, a move that could affect how quickly the total value accumulates and how easily investigators can trace the flows.
Market observers and researchers stress that the exact scope and the final total remain uncertain, with estimates continuing to evolve as more data becomes available. The reported figure approaching $89 million reflects a cumulative assessment across the affected addresses, with the currency in question remaining Bitcoin. The event has drawn scrutiny from multiple outlets and blockchain analytics providers, which are compiling transaction patterns, address clustering, and timing to understand the attacker’s behavior and the potential implications for cold-wallet security practices.
From a broader perspective, the Coldcard breach underscores ongoing concerns around hardware wallet security and the importance of robust operational safeguards for private keys. While the specifics of the vulnerability and the exploit chain remain under investigation, the case has already influenced discussions about best practices for storage, monitoring, and recovery in the crypto ecosystem. The evolving narrative—spanning multiple waves of theft, shifting recipient behavior, and on-chain consolidation tactics—highlights the challenges security teams face as attackers adapt to defensive responses and as investors seek safer ways to protect their holdings.
In summary, the Coldcard wallet attack has not only escalated in terms of total value and address count but has also revealed a changing attacker methodology and a corresponding shift in how affected holders manage risk. With losses reported in the vicinity of $89 million and a growing footprint across thousands of addresses, the incident remains a focal point for industry observers as they monitor the trajectory of the breach and its implications for hardware-wallet security practices.


