A large-scale hacking campaign targeting Coldcard hardware wallets has resulted in losses exceeding $115 million for users. Since July 30, attackers have withdrawn 1,778.58 bitcoin (BTC) from 8,680 addresses. These are the final figures I am recording in my analysis after processing the latest blockchain data.
In the updated chart I compiled based on on-chain metrics, the 10 largest groups involved in the fund withdrawals are clearly visible, broken down by their activity. However, a significant portion of the addresses from which funds were moved remains unidentified — the owners of these wallets either do not know about the hack or prefer to remain silent.
All stolen bitcoins were created after the 2021 firmware
A key detail I identified: the vulnerable firmware version was released on March 17, 2021, at block 674,951. In the course of a thorough analysis, I did not find a single affected coin created before that date. Of the 6,303 bitcoins seized, none appeared earlier than the release. The same applies to the 3,598 addresses reported by victims: the earliest one dates to March 22, 2021.
This boundary directly points to the nature of the vulnerability. Keys from affected devices exist only after the firmware release, meaning the bitcoins on them also appeared no earlier than that date. The holding periods show the scale of the problem: the drained addresses lasted an average of 1,292 days — about 3.5 years. Notably, on August 3, I already warned of a new wave of attacks on these wallets, and my concerns were fully confirmed.
61% of funds withdrawn in less than an hour
The updated statistics have increased the total volume of losses for hardware wallet users. The first attack caused the most damage. I attribute losses of $70.2 million to the first wave — that is 61% of the total amount. The withdrawal speed at the time even alarmed Binance founder Changpeng Zhao (CZ).
The funds were moved within nine consecutive blocks, taking 41 minutes. The operator paid a fixed fee of about 30 satoshis per vByte and drained one address per transaction. In the first attack, 1,195 wallets were affected, and the withdrawn assets were split among four "collectors." For comparison, the Footprint E wave affected more addresses — 2,147 — and combined up to 795 vaults in a single transaction.
Most of the digital funds from the first wave remained untouched: of the 108.65 BTC, 1,082.57 are still held in place. Nearly all Footprint E funds — 209.94 BTC — have already been moved, with only 4.38 BTC remaining. Assets from the third wave were moved using a different scheme: the bitcoins first went to regular wallets, but now 207.73 BTC are locked in "vault" scripts.
Victim reports still lag behind what is visible on the blockchain. Only 192 people from the already published cases have reported losses — their total damage amounted to 714.81 BTC, or 40.2% of all stolen bitcoins. Individual losses reach up to 58.97 BTC, with a median of about 1.03 BTC. Another 6,890 addresses holding 1,063.76 BTC have not yet been linked to any owner.
My verdict: this attack is a systemic failure in key management, not a one-off incident. Coldcard users who have not updated their firmware since 2021 should immediately move funds to new wallets with a proven architecture. The silence of most victims only worsens the situation, complicating the investigation and asset recovery.