What initially appeared to be a major hardware wallet breach has grown into a far larger forensic investigation as new evidence continues reshaping its scale.
Initial findings linked the exploit of Coldcard to 4,585 addresses in three waves and the theft of about 1,367 Bitcoin [BTC] worth roughly $88.6 million.
Later on, investigators identified another 1,912 affected addresses, which increased losses by 207.73 BTC and showed that all stolen coins remained unspent.


That behavior suggested the attacker prioritized consolidating funds instead of rushing to liquidate them. Since then the investigation has grown again. Confirmed losses now total more than 1,596 BTC worth more than $100 million across roughly 7,300 addresses.
Galaxy Research also identified 14 smaller related incidents, pushing suspected losses toward 2,000 BTC, or nearly $130 million. This exploit stands out as one of Bitcoin’s most serious failures related to custody security and raises broader questions about the resilience of hardware wallets.
Blockchain data strengthens the investigation
As the investigation broadens, blockchain forensics are also revealing how the stolen Bitcoin has been managed after the attacks.
The three confirmed theft waves remain the foundation of the case, while a fourth suspected wave could lift total losses to 2,055 BTC, or roughly $130 million, if victims confirm its inclusion.
More importantly, fund movements continue following a remarkably consistent pattern.


Ninety percent of the stolen Bitcoin remains untouched. Furthermore, each of the coins transferred through Wave 1, Wave 2, and Wave 3 sits in its receiving addresses.
That inactivity has strengthened investigators’ confidence in mapping attacker-controlled wallets and identifying additional linked addresses.
Meanwhile, newly discovered smaller theft events suggest opportunistic actors may have exploited similar conditions after the initial compromise.
As blockchain attribution improves, investigators are providing verified addresses to law enforcement, exchanges, and compliance firms, increasing the chances of tracking future movements while limiting opportunities to cash out.
The exploit challenges confidence in self-custody
Beyond exposing the exploit’s technical scope, the incident has also challenged one of Bitcoin’s longest-standing assumptions about self-custody.
The incident did not expose a flaw with self-custody. Instead, it exposed the need for well-designed wallets and independent entropy generators. It further supports best practices for user protection, including using multisig and utilizing better backup methods.
In response, Coinkite released emergency firmware, paused shipments, and urged users to generate entirely new seeds before moving funds. However, software updates cannot repair previously generated weak seeds.
Whether confidence fully recovers will depend on transparent security reviews, verifiable randomness, and clearer industry standards. The exploit may therefore reshape how users secure Bitcoin rather than discourage self-custody altogether.





Be the first to comment