A massive incident involving Coldcard hardware wallets has turned into a catastrophe for Bitcoin holders. According to my analysis of fresh data, the total damage to users has exceeded $115 million. Since July 30, attackers have withdrawn 1,778.58 BTC from 8,680 addresses, making this one of the most significant cases in the history of hardware wallets.

After conducting a detailed breakdown of affected addresses, I identified the ten largest groups from which funds were drained. However, the vast majority of addresses remain unidentified to this day—their owners either do not know about the theft or prefer to stay silent. This only worsens the problem, as the true scale of losses could be significantly higher.

The root of the problem: 2021 firmware

The key detail that stands out is that all stolen bitcoins were created after March 17, 2021, when the vulnerable firmware version was released on block 674,951. None of the 6,303 seized coins appeared before that release. The same applies to the 3,598 addresses reported by victims: the earliest one dates to March 22, 2021.

This time boundary directly points to the vulnerability. Keys on affected devices only exist after the firmware release, meaning bitcoins on them could not have appeared earlier. The holding periods show the scale of the problem: drained addresses lasted an average of 1,292 days—about 3.5 years. Notably, as early as August 3, I warned of a new wave of wallet attacks, and now those concerns have been fully confirmed.

Speed and structure of the attacks

The updated statistics have increased the total volume of losses. The first attack caused the most damage—$70.2 million, accounting for 61% of the entire amount. The withdrawal speed at that time even alarmed Binance founder Changpeng Zhao (CZ). Funds were moved across nine consecutive blocks, which took 41 minutes. The operator paid a fixed fee of about 30 satoshis per vByte and drained one address per transaction.

In the first attack, 1,195 wallets were affected, and the withdrawn assets were split among four "collectors." For comparison, the Footprint E wave affected more addresses—2,147—and combined up to 795 vaults in a single transaction. Most of the digital funds from the first wave remained untouched: out of 108.65 BTC, 1,082.57 BTC are still in place. Nearly all Footprint E funds—209.94 BTC—have already been moved, with only 4.38 BTC remaining.

Assets from the third wave were moved using a different scheme. Here, bitcoins first went to regular wallets, but now 207.73 BTC are locked in script-based "vaults." Victim reports still lag behind what is visible on the blockchain. Only 192 people from the already published cases have reported losses—their total damage amounts to 714.81 BTC, or 40.2% of all stolen bitcoins.

Individual losses reach up to 58.97 BTC, with a median of about 1.03 BTC. Another 6,890 addresses holding 1,063.76 BTC have not yet been linked to any owner.

My conclusion: this incident is a wake-up call for the entire hardware wallet industry. Even "cold" storage does not guarantee security if the firmware contains critical flaws. Users should reconsider their security protocols and consider diversifying their funds, while manufacturers should tighten code audits before releases.