Coldcard loss hits $88.6M, still moving
Galaxy Research puts Coldcard wallet losses at 1,367 BTC ($88.6M) across 4,585 addresses, as sub-1 BTC transfers spike to a 2022 high.

Galaxy Research now puts total losses from the Coldcard wallet bug at 1,367 BTC, worth $88.6 million, after tracing the damage across 4,585 addresses. The figure has climbed steadily since the flaw surfaced, and it's still moving.
What the numbers show
The bug sits in seed generation: a randomness failure that weakened recovery phrases on certain devices, letting attackers reconstruct private keys instead of brute-forcing them. Galaxy's address count, 4,585, is the first hard measure of how wide the exposure ran, more than double earlier informal estimates.
The knock-on effect shows up in transfer data. CryptoQuant head of research Julio Moreno reported that Bitcoin transfers under 1 BTC hit 39,600 BTC in a single day on Friday, the highest sub-1 BTC volume since November 16, 2022, when 39,900 BTC moved days after FTX's bankruptcy filing. Moreno called it a sign that "the Bitcoin plebs" were finally moving exposed coins after sitting on vulnerable keys, some for years. Cointelegraph's report has the full breakdown.
Why the timing matters
A seed generation flaw is worse than a stolen password because it doesn't require a breach. If the randomness pool was ever thin, anyone who worked out the pattern could regenerate a match without touching Coldcard's servers or a user's device. That's why losses climbed for weeks after disclosure: attackers didn't need new access, they needed time to search.
The sub-1 BTC transfer spike is the real tell. Retail holders don't move small amounts en masse unless something specific forces the decision, and matching FTX-era volume says people are treating this as an emergency migration, not routine housekeeping. Self-custody's pitch has always been that no exchange can freeze your coins. A hardware wallet that silently weakens your own keys undercuts that pitch from the inside, and it does so quietly enough that most holders had no way to know they were exposed until researchers went looking.
The gap between when the bug shipped and when Galaxy could size the damage also says something about detection speed in this space. Address-level forensics took Galaxy real analytical work to assemble after the fact. That lag is the actual vulnerability window, and it's longer than any single device flaw.
What to watch
Watch whether Galaxy's address count keeps rising in the next update. If 4,585 holds steady, the bulk of exposed holders have likely moved funds already. If it climbs again, it means either more affected devices are being identified or attackers are still working through addresses faster than users are securing them.
