[ Story · STORY ]

Coldcard loss hits $88.6M, still moving

Galaxy Research puts Coldcard wallet losses at 1,367 BTC ($88.6M) across 4,585 addresses, as sub-1 BTC transfers spike to a 2022 high.

STORY·August 2, 2026·3 min read·By Gintautas Nekrosius
A cracked seed pod scattering coins into fragmented negative space, cream background, single red crack line
A weak seed, a wide crack: 4,585 addresses exposed at once.

Galaxy Research now puts total losses from the Coldcard wallet bug at 1,367 BTC, worth $88.6 million, after tracing the damage across 4,585 addresses. The figure has climbed steadily since the flaw surfaced, and it's still moving.

What the numbers show

The bug sits in seed generation: a randomness failure that weakened recovery phrases on certain devices, letting attackers reconstruct private keys instead of brute-forcing them. Galaxy's address count, 4,585, is the first hard measure of how wide the exposure ran, more than double earlier informal estimates.

The knock-on effect shows up in transfer data. CryptoQuant head of research Julio Moreno reported that Bitcoin transfers under 1 BTC hit 39,600 BTC in a single day on Friday, the highest sub-1 BTC volume since November 16, 2022, when 39,900 BTC moved days after FTX's bankruptcy filing. Moreno called it a sign that "the Bitcoin plebs" were finally moving exposed coins after sitting on vulnerable keys, some for years. Cointelegraph's report has the full breakdown.

Why the timing matters

A seed generation flaw is worse than a stolen password because it doesn't require a breach. If the randomness pool was ever thin, anyone who worked out the pattern could regenerate a match without touching Coldcard's servers or a user's device. That's why losses climbed for weeks after disclosure: attackers didn't need new access, they needed time to search.

The sub-1 BTC transfer spike is the real tell. Retail holders don't move small amounts en masse unless something specific forces the decision, and matching FTX-era volume says people are treating this as an emergency migration, not routine housekeeping. Self-custody's pitch has always been that no exchange can freeze your coins. A hardware wallet that silently weakens your own keys undercuts that pitch from the inside, and it does so quietly enough that most holders had no way to know they were exposed until researchers went looking.

The gap between when the bug shipped and when Galaxy could size the damage also says something about detection speed in this space. Address-level forensics took Galaxy real analytical work to assemble after the fact. That lag is the actual vulnerability window, and it's longer than any single device flaw.

What to watch

Watch whether Galaxy's address count keeps rising in the next update. If 4,585 holds steady, the bulk of exposed holders have likely moved funds already. If it climbs again, it means either more affected devices are being identified or attackers are still working through addresses faster than users are securing them.

Gintautas Nekrosius is the founder and editor of Stack and Story. He spent more than a decade in technology and crypto, including senior marketing roles at companies in the Animoca Brands and NordVPN groups, and worked on token launches and go-to-market from the inside. He started Stack and Story to write the independent read he could not find: crypto and markets explained plainly, by someone who has seen how the machine works. The publication holds no tokens and takes no trades.

DisclosureStack and Story holds no position in the assets discussed and earns nothing from their movement. This is analysis, not financial advice. Do your own research.

Understand crypto. Decide for yourself.

The numbers that moved, and the reason they did, every Sunday, free.

Free · Independent · Unsubscribe anytime · Privacy