Coldcard hack: three trackers, three totals
CryptoQuant confirms 1,432 BTC stolen in the Coldcard hack, while Galaxy and TRM Labs trace figures closer to 1,816 BTC.

A hardware-wallet hack against Coldcard users has produced three different loss figures from three different investigators, and none of them claim to be final.
What the trackers actually agree on
CryptoQuant puts confirmed losses at 1,432 BTC, a number built strictly from victims who publicly disclosed wallet addresses or transaction IDs. Galaxy Research's high-confidence minimum sits at 1,730 BTC as of Tuesday, up from an earlier estimate as high as 1,816 BTC that Galaxy's Alex Thorn now calls a potential figure rather than a confirmed one. TRM Labs lands in the same range as Galaxy, estimating roughly 1,816 BTC drained from more than 5,200 addresses across four separate attack waves.
The gap between the low and high estimates is close to 400 BTC, worth roughly $25 million at current prices. Galaxy's own breakdown shows why: it has directly confirmed 450+ BTC from victim reports, used those reports to identify a further set of victims pushing the corroborated total past 730 BTC, and is still withholding "many more BTC we suspect but for which we lack sufficient corroboration," per Thorn. CryptoQuant's Julio Moreno takes the opposite posture, treating unconfirmed onchain patterns as a source of false positives rather than a basis for inflating the count. Chainalysis says it hasn't run an independent tally at all, and investigator ZachXBT has said he has no plans to trace the incident.
Self-custody breaks the usual playbook
Exchange hacks come with a ledger. There's a hot wallet, a known set of accounts, and a company with legal exposure to name a number quickly. Coldcard's theft has none of that. The 5,200-plus addresses TRM cites aren't a customer list, they're a pattern match, and every one of those matches has to be weighed against the risk of counting someone's unrelated transaction as stolen funds. That's the real divide between CryptoQuant's floor and Galaxy's ceiling: one side counts what's proven, the other counts what's probable, and both are defensible. Neither is complete. Moreno's own framing is the honest one, that the total "will always be an estimation" because investigators can only confirm what victims choose to disclose.
That dependency on disclosure is the structural weakness in every self-custody incident. A victim who doesn't post an address, doesn't file a report, or doesn't even realize a specific hack drained a device stays invisible to every tracker at once. TRM's Ari Redbord expects the number to keep moving before it settles, which is a polite way of saying nobody currently has the real total and nobody will for a while.
What would tighten the number
Watch whether Galaxy's corroborated victim-report tally, currently past 730 BTC, keeps closing the gap with its onchain-pattern estimate of 1,730 BTC. If direct confirmations catch up to the higher figure, that's a sign the pattern-matching was right. If the gap stays wide for weeks, it means a meaningful share of the loss will never get a name attached to it, and the final number stays a range rather than a fact.
