Speaking on Bits + Bips, the Galaxy Digital researcher said Coldcard victims “did nothing wrong,” noting he has found roughly 14 more attacker patterns not yet made public.

Coldcard Bitcoin Theft Tops $100 Million as Galaxy’s Alex Thorn Tracks a Fourth Wave
Posted August 5, 2026 at 11:00 am EST.
Alex Thorn, head of research at Galaxy Digital, said on the Bits + Bips podcast that an exploit of Coldcard hardware wallets has drained “well over $100 million” in bitcoin from self-custodied holders, and walked through the wave-by-wave forensic trail he has been using to track the attackers — including a suspected fourth wave and about 14 additional attacker patterns he said he had not yet reported.
The episode is one of the fullest public accounts yet of who was hit and why. Thorn, who has been tracing the theft onchain, said he had confirmed three waves and a fourth still in the “medium to high confidence” range.
“Well over $100 million”
“We’re well over $100 million of self-custodied Bitcoin,” Thorn said on the podcast, adding that even without the fourth wave the losses cleared that mark. “I would place it more in the 1600 BTC range.” He called it “unprecedented as far as I’m aware” for a distributed self-custody hack.
The tally has climbed since the taping. By Thorn’s count, three confirmed waves have taken about 1,367 BTC — near $89 million — from roughly 4,585 addresses. Folding in a suspected fourth sweep he flagged August 3, which moved hundreds more coins through a burst of blocks at about 45 times the normal rate, the total rises to roughly 1,815 BTC, or near $114 million, across some 5,294 addresses.
Fourteen more patterns
Beyond the numbered waves, Thorn said on the show he had found still more attackers — “14 other identifiable patterns that we have found that do not appear related to any of those waves, but do have verifiable victims” — that he had not folded into the headline count and planned to detail on X.
A silent firmware flaw
The exploit traces to a March 17, 2021 Coldcard firmware update that added the company’s own random number generator but, Thorn said on the podcast, “miswired it” so that key generation would “fail silently” and fall back to a generator with “way too weak entropy” to be secure. Attackers with enough compute could then reproduce the keys and sweep the coins.
“These people did nothing wrong,” Thorn said on the show. “In fact, they did everything right.” He described the victims as long-term holders — the average stolen coin had sat untouched for nearly four years — rather than speculators, and urged anyone holding bitcoin on a single-signature Coldcard address to “move those coins off as soon as possible.”
Coinkite takes “full accountability”
Coinkite, the Canadian company that makes Coldcard, has taken public responsibility. Chief executive Rodolfo Novak apologized on X, writing that the company was “heartbroken” and taking “full accountability for the firmware bug,” and Coinkite has shipped a fixed firmware. The company warned, however, that the update does not protect seeds already generated on the flawed software; those funds have to be moved to a wallet created with the fix.
Thorn also pointed to a narrow recovery path. Because some of the theft transactions signal replace-by-fee, a victim who spots their coins still unconfirmed in the mempool may be able to outbid the attacker and move the funds first. He urged victims to file reports with the FBI’s IC3 and their local police, and to keep the compromised device as evidence.
Related Listen: Strategy Sells $216M in Bitcoin. Is Saylor a Buyer or a Seller Now?: Bits + Bips
AI-assisted content: This article was produced with the assistance of AI tools and was reviewed, edited, and fact-checked by a member of the Unchained editorial team before publication.
Bitcoin,Alex Thorn,Bitcoin security,Bits + Bips,Coinkite,Coldcard,Galaxy DigitalAlex Thorn,Bitcoin security,Bits + Bips,Coinkite,Coldcard,Galaxy Digital#Coldcard #Bitcoin #Theft #Tops #Million #Galaxys #Alex #Thorn #Tracks #Fourth #Wave1785944568

