Galaxy Research raised its observed total for the Coldcard weak-entropy sweeps to 1,367.05 bitcoin (about $88.6–89 million) across 4,585 addresses after flagging a third wave that moved roughly 208 BTC from 1,912 addresses. That is more than double the ~594 BTC first-wave figure PTYcoin covered when Coinkite published its initial advisory on 30 July.
CoinDesk and The Hacker News matched the same combined totals. Galaxy stresses the numbers come from on-chain clustering, not a cryptographic re-derivation of every victim seed: the firm has not brute-forced every address to prove Coldcard entropy was the cause.
How the three waves look
Galaxy’s public tracking, summarized by CoinDesk, breaks the activity into three clusters between 30 July and the start of August:
| Wave | Rough scale | On-chain shape (Galaxy / CoinDesk) |
|---|---|---|
| 1 (30 July) | ~1,083 BTC from 1,196 addresses in ~41 minutes | One victim per spend; shared collector addresses; plain single-key outputs |
| 2 (31 July) | ~76 BTC from 1,478 addresses over ~3h 42m; running total ~1,159 BTC / 2,673 addresses | ~0.05 BTC average — the smallest of the three; same collector pattern as wave 1 (Galaxy’s working assumption) |
| 3 | ~208 BTC from 1,912 addresses | ~0.1 BTC average; unique destinations; P2WSH vaults; ~6 victims per batch |
Wave three is the new operational story. Instead of dumping many victims into a handful of easy-to-tag collector addresses, it sends each drained wallet to its own destination and parks coins in pay-to-witness-script-hash (P2WSH) outputs, which can hide multisig or timelock scripts until the first spend. Galaxy is monitoring 293 of those unspent P2WSH vaults; the first spends will reveal the scripts underneath.
Galaxy says it is confident each wave is one operator internally, and it will not formally link all three to the same actor. Stolen balances from the mapped endpoints remain largely unspent on-chain. On 2 August the firm posted that the exploit is ongoing, that it has reported about 600 suspected attacker-held addresses to U.S. investigators and compliance teams, and that victims who share addresses and TXIDs (without personal data) are still helping map new clusters.
What broke, and what Coinkite has fixed since
The root cause is unchanged from the first advisory: a March 2021 firmware path that sent seed generation through a weak software PRNG instead of the chip’s hardware RNG, shrinking effective entropy far below the 128-bit BIP-39 target. Attackers who can enumerate that reduced keyspace rebuild candidate seeds offline and match funded addresses on the public chain. No one needs physical access to a Coldcard.
Coinkite’s advisory, updated 1 August 2026, now lists fixed firmware for every affected track:
- Mk2 / Mk3: 4.2.0 or later
- Mk4 / Mk5 standard: 5.6.0+; Edge 6.6.0X+
- Q standard: 1.5.0Q+; Edge 6.6.0QX+
A firmware upgrade does not repair a seed already written years ago. You generate a new seed on fixed firmware and migrate. Coinkite still treats seeds built with ≥50 fair, private dice rolls (via Add Dice Rolls) as outside this RNG failure alone, and still wants passphrase users to migrate as soon as practical. TAPSIGNER, OPENDIME, and SATSCARD stay out of scope.
Block’s engineering write-up explains the integration mistake that bound production builds to MicroPython’s software fallback; Coinkite’s own entropy technical backgrounder puts Mk3-class exposure near ~40 bits and newer models near ~72 bits until the hotfix builds.
Who still needs to move
The urgent cohort is the same as last week, only larger in the on-chain sample: single-signature wallets whose seed was device-generated on vulnerable firmware, without enough independent dice entropy and without a strong BIP-39 passphrase. Multisig only helps when the quorum is not built entirely from weak device seeds. Galaxy notes the value is concentrated in larger balances while the address count is dominated by sub-1 BTC wallets (the shape of long-term self-custody, not corporate treasuries).
If you already migrated after the 30–31 July posts, you do not need a second migration for this news alone. If you still hold funds on a Coldcard-generated single-sig seed from the vulnerable window, treat the third wave as a reason to finish the move carefully this week:
- Install the fixed build for your model from Coinkite’s official pages, then confirm the version on-device.
- Create a new seed; verify the backup and a receive address on the device screen.
- Test-send a small amount; only then move the rest.
- Keep the old backup until the new wallet is proven.
Mk2/Mk3 owners who only have that device can now complete a full migration on 4.2.0 without buying newer hardware. Coinkite’s one-device steps (verify old backup → new seed → test → residual move) remain the safer path than a rushed bulk send.
Takeaway
The story that opened with a 25–41 minute first sweep is now a multi-day, multi-wave campaign that researchers still mark as active. Hardware wallets remove exchange counterparty risk; they do not remove firmware and entropy risk, and offline storage only works if the seed was generated with real randomness. For holders who treat a Coldcard as a multi-year vault, the practical answer is still boring: confirm which model and firmware created each seed, treat weak-entropy single-sig wallets as compromised for planning, upgrade before minting a replacement key, and verify every address on the device screen.
This is a security incident report, not investment advice. If coins sit on an affected seed, follow Coinkite’s migration checklist before the next sweep finds them.



