In brief

The Coldcard exploit is ongoing, with Galaxy Research now tracking about $88.6 million stolen across 4,585 addresses in three waves.

Galaxy's Alex Thorn described the sweeps as deliberate and likely LLM-orchestrated, warning that every single-sig Coldcard address created after the March 2021 firmware flaw will eventually be drained.

The breach has spurred an unusual reversal of the "not your keys, not your coins" ethos as users move Bitcoin back to exchanges.

The theft of Bitcoin from compromised Coldcard hardware wallets is still underway, with researchers now tracking losses of roughly $88 million and warning that every vulnerable device will eventually be emptied.Galaxy Research said Saturday it has identified a third wave of thefts, in which 207.73 BTC was drained, lifting its observed tally to about 1,367 BTC—around $88.6 million—across 4,585 addresses. The firm called the exploit ongoing and urged anyone holding single-signature funds on a Coldcard to move them at once. Galaxy said it has flagged roughly 600 suspected attacker addresses to federal investigators, compliance firms and cross-industry cyber investigators, crediting victims who shared transaction details for helping map the on-chain patterns.“I continue to investigate and add new Coldcard victim and attacker addresses to our investigation database,” Galaxy’s head of research Alex Thorn posted to X. “The attack is ongoing—move your funds off Coldcard-generated addresses immediately if you have not done so.”