Coldcard Bitcoin Hack Leaves 87 Percent Of Stolen Funds Unmoved

10 min read
3 views
Aug 25, 2026

More than 87 percent of the Bitcoin taken in the Coldcard exploit still sits untouched in attacker wallets. Researchers keep watching those addresses, waiting for the first big move that could change everything.

Financial market analysis from 25/08/2026. Market conditions may have changed since publication.

I still remember the first time I heard about a hardware wallet that was supposed to be nearly untouchable. Cold storage felt like the last real fortress for people who refused to leave their Bitcoin on exchanges. Then the numbers started rolling in this summer, and that fortress suddenly looked a lot less solid. More than 1,789 Bitcoin vanished from thousands of addresses, worth over $114 million at the moment of the thefts. What surprised me most was not the size of the haul. It was the fact that roughly 87 percent of those coins have not moved since.

Why Most Of The Stolen Bitcoin Still Sits Quietly

Researchers following the trail report that 1,561 Bitcoin remain parked in a handful of collection and holding addresses controlled by the attackers. That is 87.3 percent of the total amount linked to the Coldcard exploit. The coins taken during the earliest waves have stayed completely still. Later batches show more activity, but the bulk of the money has not been spent, mixed, or sent anywhere obvious.

In my view, this quiet period is almost more interesting than the theft itself. When large amounts of stolen crypto sit motionless for weeks, it usually means the people behind the operation are either extremely patient or still figuring out how to cash out without leaving a clear path. Either way, the longer those coins stay put, the clearer the on-chain picture becomes for investigators.

How The Numbers Stack Up Across Thousands Of Addresses

The latest tally points to 8,865 addresses that lost funds. The median loss per address looks tiny at first glance, only 0.00152 Bitcoin. The average climbs to 0.20184 Bitcoin. That gap tells a familiar story. A large number of people lost small amounts while a smaller group of heavier holders absorbed the bigger hits.

Victim reports paint a different picture. Out of 221 people who came forward, the median reported loss reached 1.04272 Bitcoin and the average sat at 3.57792 Bitcoin. Those 221 reports alone account for 790.72 Bitcoin, which is already 44.2 percent of the total attributed to the exploit. At least half of the people who filed reports lost one full Bitcoin or more. That is not a trivial sum for most individuals.

Another detail that stands out is how long the coins had been sitting before they disappeared. Across the broader set of addresses the median dormancy period was 3.2 years. The average stretched to 3.6 years. In the victim reports the numbers were similar, with a median of 3.25 years and an average of 2.99 years. These were not freshly deposited coins. They were long-term holdings that people clearly believed were safe.

The median means at least half of the reporting victims lost one Bitcoin or more.

That kind of dormancy makes the theft feel especially painful. Someone who set up a hardware wallet years ago, wrote down the seed, and then largely forgot about it suddenly discovers the balance is gone. The psychological hit is real.

What Researchers Believe Went Wrong With The Devices

The root problem appears to trace back to a firmware issue introduced in March 2021. A build configuration error caused some devices to fall back on a weaker software random number generator instead of relying fully on the hardware entropy source. When the randomness used to create a seed is weaker than expected, the range of possible private keys shrinks. With enough computing power an attacker can brute-force those keys without ever touching the physical device.

I have always liked the idea of air-gapped wallets and dual secure elements. They sound reassuring. Yet this incident shows that even careful design can be undermined by a single configuration mistake that sits unnoticed for years. The fact that the flaw affected seed generation rather than the signing process itself is particularly important. Updating the firmware later does not fix a seed that was already created with weak entropy. The only real remedy is to generate a completely new seed on a known-good device and move the coins.

Security researchers have noted that the resulting key strength could drop low enough for practical recovery through computational means. That is a different threat model from someone stealing the physical wallet or tricking the owner into signing a malicious transaction. It is quieter and harder to detect until the coins are already gone.

Early Waves Versus Later Activity

All Bitcoin linked to the first three identified attack waves has remained unmoved. That is useful for investigators. Those coins form a relatively clean record of where the funds ended up after the initial thefts. Later waves show different behavior. Some of those coins have started moving through CoinJoin transactions and peel chains.

CoinJoin mixes inputs from multiple participants so that linking any single input to a specific output becomes more difficult. Peel chains work by repeatedly sending small amounts from a larger balance into new addresses, creating long trails that take time to follow. Both techniques are well known in the privacy community. Seeing them appear after the quieter early waves suggests the people involved may have adjusted their approach as the investigation progressed.

Some analysts have pointed out that differences in transaction structure across the waves could indicate more than one group of attackers. That possibility has not been confirmed, but it remains on the table. Multiple actors exploiting the same vulnerability at slightly different times would not be surprising given how long the firmware issue appears to have existed.


How Investigators Are Tracking The Funds

On-chain analysis continues to map both high-confidence and medium-confidence addresses. Including the medium-confidence set would raise the estimated total to around 1,824 Bitcoin, roughly $140 million at the prices prevailing when each theft occurred. The confirmed figure of 1,789.28 Bitcoin already represents a substantial sum.

Researchers have shared identified attacker addresses with exchanges, compliance firms, and law enforcement. The hope is that if any of the stolen coins eventually land on a centralized platform, those funds can be frozen before they are converted into fiat or other assets. So far the bulk of the early-wave coins have not taken that step. They remain in addresses that appear to be under direct attacker control.

I find the monitoring of those quiet addresses particularly valuable. As long as the coins stay there, every outgoing transaction becomes a potential new lead. The moment a large portion starts moving, the privacy techniques used will determine how hard the next stage of tracking becomes.

What This Means For Hardware Wallet Users

Hardware wallets were never marketed as perfect. They were sold as a meaningful improvement over software wallets and exchange custody. Most of the time that improvement holds. Yet this case shows that a subtle flaw in seed generation can undermine the entire security model years after the device left the factory.

People who still hold coins on devices that may have been affected face a clear choice. Generating a new seed on a device with known good entropy and transferring the funds is the only way to close the exposure. Simply updating the firmware does not rewrite history for seeds created under the weaker conditions.

The broader conversation around randomness has been growing for months. Weak entropy in recovery-phrase generation has already caused losses in software wallets earlier this year. Hardware was supposed to be the stronger option. When even that layer shows cracks, confidence takes a hit across the entire self-custody space.

  • Check whether your device ever ran the affected firmware period
  • Consider generating a fresh seed on a new or verified device
  • Move funds only after confirming the new setup works correctly
  • Keep detailed records of the migration process
  • Avoid reusing any old seed that might have been generated under the weak conditions

Those steps sound basic, yet many people delay them because the process feels cumbersome. In a situation like this, delay carries real cost.

The Human Side Of Long-Dormant Coins

One aspect that does not get enough attention is the emotional weight of discovering a multi-year cold storage balance is gone. These were not day-trading positions. Many of the addresses had sat untouched for more than three years. People treated them as long-term savings, emergency reserves, or generational holdings.

When the median dormancy sits above three years, the theft stops feeling like a technical incident and starts feeling personal. Someone who carefully followed best practices at the time, bought a reputable device, and then largely forgot about the coins now has to confront the fact that the protection was incomplete.

I have spoken with people who went through similar experiences with other exploits. The common thread is a sense of betrayal by the tools they trusted most. Rebuilding that trust takes time, and some never fully regain it.

Why The Unmoved Coins Matter More Than The Moving Ones

The coins that have begun circulating through CoinJoin and peel chains create noise. They force investigators to spend more resources following complex trails. The 1,561 Bitcoin that remain still form a clearer target. As long as those holdings stay concentrated, the pressure on the attackers increases. Every day that passes without movement is another day the addresses remain known and watched.

From a practical standpoint, large dormant balances of stolen funds often end up being the ones that eventually get recovered or frozen if they ever touch a regulated service. The longer they sit, the more time exchanges and compliance teams have to prepare watchlists.

Of course, sophisticated actors can wait years. Some high-profile thefts from the past only saw significant movement long after the original headlines faded. Patience on both sides is part of the game.

Broader Lessons For Self-Custody Practices

This episode reinforces a few principles that many experienced holders already follow but that newer users sometimes overlook. First, no single device or software should be treated as permanently trustworthy without periodic verification. Second, seed generation is the most critical moment in the life of a wallet. Any weakness introduced there is permanent for that particular seed. Third, diversification across devices, seed origins, and even storage methods reduces the blast radius of any single failure.

Air-gapped workflows, dual secure elements, and open-source firmware remain valuable. They simply are not sufficient by themselves when the randomness source is compromised upstream. Users need to understand the full chain of trust, not just the marketing claims around physical security.

Perhaps the most practical takeaway is the importance of testing recovery procedures before they are needed. Generating a new seed and verifying that funds can be moved cleanly is something every serious holder should practice. Waiting until a vulnerability is publicly known is usually too late for the coins already at risk.

MetricAddress-Level DataVictim Reports
Number of Cases8,865 addresses221 reports
Total Bitcoin1,789.28 BTC790.72 BTC
Median Loss0.00152 BTC1.04272 BTC
Average Loss0.20184 BTC3.57792 BTC
Median Dormancy3.2 years3.25 years

Looking at those figures side by side makes the distribution clear. The address-level data captures many small losses, while the people who chose to report tend to have lost more significant amounts.

Where Things Stand Right Now

As of the most recent updates, the majority of the early-wave coins remain in place. Later activity shows attempts at obfuscation, but the overall picture is still dominated by the unmoved holdings. Researchers continue refining the list of related addresses and sharing information with relevant parties.

The current value of the stolen Bitcoin sits higher than the original $114.7 million figure because prices have moved since the thefts. One recent estimate placed the total around $138.8 million. That appreciation benefits the holders of those addresses for now, yet it also increases the incentive for investigators to keep watching.

No public attribution to specific individuals or groups has been confirmed. Differences in behavior across waves leave open the possibility of multiple independent actors. Until more movement occurs or additional technical evidence surfaces, that question remains unsettled.

Practical Steps For Anyone Still Holding Cold Storage

If you have Bitcoin sitting on a hardware wallet purchased or set up during the relevant period, the cautious approach is straightforward even if it requires effort. Create a new seed using a device whose entropy source you trust. Verify the new wallet thoroughly with small test amounts. Then move the bulk of the funds. Destroy or securely store the old seed material so it cannot be reused accidentally.

Some people prefer to spread holdings across multiple independent setups rather than consolidating everything into one new seed. That approach reduces the impact of any future single-point failure. Others maintain a mix of hardware and carefully managed software solutions for different portions of their stack. There is no universal perfect answer, only trade-offs that fit individual risk tolerance.

One habit I have found useful is documenting the exact firmware version and setup date for every device. When a vulnerability surfaces years later, that record makes it much easier to assess exposure quickly.

The Longer-Term Impact On Trust In Cold Storage

Incidents like this do not destroy the case for self-custody. They do force a more realistic assessment of the risks. Hardware wallets remain superior to leaving large balances on exchanges for most people. They simply are not magic. Every layer of the stack, including the quality of the random numbers used at the beginning, needs ongoing scrutiny.

Manufacturers will likely respond with clearer guidance, improved testing of entropy sources, and more transparent communication about past firmware versions. Users will become more cautious about assuming that “set it and forget it” is a safe strategy for multi-year holdings. Both developments are healthy, even if they arrive after real losses.

The 87 percent of coins that still have not moved serve as a reminder that the story is not finished. Those addresses remain under observation. Any significant outflow will generate new data, new trails, and potentially new opportunities for recovery. Until then, the quiet itself is information.

For anyone who has treated hardware wallets as the final word in security, this episode is an invitation to revisit assumptions. The tools are still valuable. The assumptions around their invulnerability needed updating. That process is already underway across the community, and the more carefully it is done, the fewer similar surprises we are likely to see in the years ahead.

The combination of long dormancy, a subtle firmware flaw, and a large unmoved balance creates a distinctive case study. It is less dramatic than a flashy exchange breach, yet it may prove more instructive for the people who actually hold their own keys. Paying attention to the details now can help prevent the next quiet drain of long-held coins.

If you're prepared to invest in a company, then you ought to be able to explain why in simple language that a fifth grader could understand, and quickly enough so the fifth grader won't get bored.
— Peter Lynch
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>