
Galaxy Research tallies $115M in losses from the Coldcard firmware flaw and says it has spoken to 200+ victims; Coinkite and TRM Labs now host live updates.
Losses tied to the Coldcard hardware wallet breach now exceed $115 million, according to Galaxy Research.
Galaxy Research posted the figure Sunday (Aug. 16), saying it reflects data through Aug. 13. The firm said it has spoken with more than 200 victims “to support them and gather intelligence on the attackers.”
The losses stem from a vulnerability affecting older versions of firmware used by Coldcard, a Bitcoin hardware wallet made by Coinkite. Attackers exploited a five-year-old flaw in the randomness used to generate some wallets’ recovery phrases, which made it easier to discover the private keys derived from them and drain bitcoin from thousands of users. The defect went undetected until the thefts began.
Coinkite and TRM Labs have each set up pages to provide updates on the theft. Twenty-One Million, a company that builds crypto tracking and calculation tools, also maintains a page that notes some trackers place losses above $130 million.
“This is one of the largest hardware-wallet failures in Bitcoin’s history, and coverage broadly describes it as one of the largest single crypto thefts of 2026,” Twenty-One Million said.
Twenty-One Million noted that weak randomness has affected bitcoin wallets before. The 2023 Milk Sad bug and the 2022 Wintermute hack both involved predictable randomness that looked identical to real randomness until someone checked, the company said. Open-source, auditable hardware eventually exposes such bugs because they sit in public code, Twenty-One Million said. The same trait means open source catches problems eventually, not instantly, and does not replace extra protections such as passphrases or multisig, the company added.
PYMNTS wrote earlier this month that the Coldcard failure undercuts the idea that offline storage ends the security discussion. “A device disconnected from the internet can still generate a vulnerable key,” the report said. Open-source software can still hide a flaw, the report said, and assets can vanish without the device ever leaving a safe.
Institutional custodians face a narrower lesson from the breach, PYMNTS argued. The critical security questions sit outside the blockchain, in the hardware and software and in the governance and operational controls that determine who can produce a valid signature.
Losses from crypto-related thefts reached about $972 million in the first seven months of 2026, according to a recent CoinDesk report. The Coldcard case is among them.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.