The Coldcard theft is no longer a $38 million story, or a $70 million story, or an $89 million story. A fourth wave of thefts over the weekend pushed the running total to approximately 1,816 BTC — nearly $116 million — drained from more than 5,200 individual addresses since the exploit began last Thursday, per Fortune. It is now among the largest thefts ever to hit self-custodied Bitcoin — and it retains the strangest property of the whole affair: as far as public tracing shows, the attacker has not spent a single stolen coin.

The ledger, five days in

SnapshotSource & dateStolen BTCAddresses hit
Wave 1 (Jul 30–31)Galaxy Research via CoinDesk, Jul 31594.48 in ~25 min; 1,082.65 linked total~500 drained; 1,196 linked
Waves 1–3 cumulativeGalaxy via CoinDesk/KuCoin, Aug 21,367 (~$88.6M)~4,500–4,585
Wave 4 cumulativeFortune, Aug 3~1,816 (~$116M)5,200+

The figures differ across sources because they are snapshots of a moving target, counted by different clustering methods — we present them dated rather than reconciled. The direction is what matters: each wave has reached deeper into smaller wallets, consistent with Galaxy’s earlier finding that wave three averaged just ~0.11 BTC per victim. The attacker is working down-market through the vulnerable key space — which Galaxy described as increasingly “picked over.”

Why the fix cannot reach the victims

The root cause, confirmed by security researchers this week, is a March 2021 firmware integration error that routed seed generation to a deterministic software pseudorandom number generator instead of the STM32 chip’s hardware RNG — collapsing the effective entropy behind affected recovery phrases until they became guessable at scale, per The Hacker News. Coinkite has shipped a firmware update that prevents the flaw from affecting newly generated wallets — but as Fortune notes, updating does nothing for seeds already created under the buggy firmware. The only remedy is migration: generate a fresh seed on patched firmware (or with verifiable dice-roll entropy) and sweep the funds. Our step-by-step sweep guide and entropy explainer cover the procedure and the underlying math; if you generated a Coldcard seed between March 2021 and the recent patches, treat migration as urgent rather than precautionary.

$116 million, frozen in place

Our L1 marker — set August 1 to watch the consolidated 562 BTC address — remains unmoved, and the pattern now extends across the entire haul: the stolen coins sit unspent in attacker-controlled addresses, per Galaxy’s tracking relayed by TheStreet. Galaxy offers two explanations: the operator is waiting for scrutiny to fade, or has no viable way to launder a sum this visible. Both may be true. A nine-figure Bitcoin hoard whose provenance is documented block-by-block is one of the hardest sums of money on earth to spend — every exchange compliance desk, analytics firm and OFAC watcher has these addresses flagged. For the market, dormancy defuses the forced-selling scenario for now; a sudden move of these coins toward exchanges would be the tape’s clearest sell-pressure warning, which is why it stays a standing marker through Saturday and, informally, well beyond.

The uncomfortable beneficiary

The incident’s second-order effect is showing up where July’s flow data said it would: in the custody debate. CoinDesk reported that the exploit is shaking faith in self-custody and may push a cohort of holders toward ETFs — the exact instrument self-custody advocates built hardware wallets to make unnecessary. Both readings of that migration are defensible: institutional custody has its own failure modes (it concentrates them), while the Coldcard flaw shows that self-custody’s security is only as good as the least-audited firmware commit in the chain. Crypto markets spent a fifth straight session trading heavy under the story, per FXStreet, with Bitcoin holding near $63,900 Tuesday as the macro tape improved around it. The honest summary for holders: this was a vendor-specific engineering failure, not a break of Bitcoin’s cryptography — and the response it demands is verification discipline, not surrender of keys. Check your device, check your firmware generation date, and if you are in the affected window, sweep.

FAQ

Am I affected if I own a Coldcard?

The flaw affects seeds generated on the buggy firmware line dating to March 2021. If your seed was generated on affected firmware — regardless of what you run today — migrate to a fresh seed on patched firmware. Seeds generated with user-supplied dice-roll entropy are not exposed to the PRNG flaw.

Does updating firmware protect me?

Only for wallets created after the update. Updating cannot repair a recovery phrase that was generated with weak entropy; only moving funds to a new seed does.

Has the attacker sold the stolen Bitcoin?

No movement has been observed as of August 4. The stolen funds sit unspent in attacker-controlled addresses that analytics firms and exchanges have flagged, making liquidation extremely difficult.

Is this a flaw in Bitcoin itself?

No. Bitcoin’s cryptography is untouched. The failure was in one vendor’s firmware, which generated predictable recovery phrases — an implementation bug, not a protocol break.

Investment disclaimer: This article is for informational and educational purposes only and does not constitute investment, financial, legal, or tax advice. Bitcoin and cryptocurrencies are volatile assets; you can lose some or all of your capital. Always do your own research and consult a licensed financial advisor before making investment decisions.