Galaxy Counts at Least Fifteen Attackers in the Coldcard Exploit

Galaxy Research counted at least 15 independent attackers sweeping bitcoin out of vulnerable Coldcard hardware wallets, the firm said on Tuesday 4 August. Before that finding the sweeps had been reported as the work of a small number of operators running coordinated waves between 30 July and 3 August. Fifteen separate participants means the method is reproducible by anyone willing to run it, which changes the shape of the incident without changing its size. Galaxy put confirmed losses at 1,596 BTC, about $100 million, and the suspected total at 2,055 BTC, roughly $130 million, once a disputed fourth wave is counted. Running totals published by different outlets over the preceding days do not reconcile with each other.
Fifteen operators, about 600 addresses
Galaxy identified roughly 600 suspected attacker addresses across the campaign. As of the firm's 4 August count, that campaign covered three confirmed waves, a fourth Galaxy said it was still verifying, and 14 smaller incidents outside the wave structure. The fourth wave accounted for about 449 BTC taken from roughly 709 addresses, and Galaxy had not verified it at the time of writing. Seventy-three victims had come forward to help trace their coins. The defect itself was already on the record: it traces to a build flag left switched off in a 2021 firmware configuration, which sent seed generation to a deterministic fallback random-number generator instead of the chip's hardware source. Recovery phrases produced that way are guessable.
Fifteen operators is a different problem from a single attacker with a private method. That attacker produces waves. Fifteen produce a race, because every vulnerable address that has not been emptied is a claim any of them can take. Coins swept had been dormant an average of 3.18 years on Galaxy's figures, a pattern that fits systematic scanning of long-untouched addresses. It does not fit the targeting of particular holders. The fourth wave came in smaller than the first sweep on 30 July, because the largest balances went early.
$100 million confirmed against $130 million suspected
The Crypto Times published two pieces on 4 August that disagree with each other. Its report on the fifteen-attacker finding put affected addresses at "over 7,700", while its companion piece the same day gave "approximately 7,300." Neither is a correction of the other, and we could not establish which supersedes which. The dollar figures are looser still. CoinDesk had put losses close to $89 million on 2 August and possibly near $114 million on 3 August, and the split published on 4 August spans $100 million to $130 million. Any number quoted here means something only with the outlet and the timestamp attached to it.
Thorn points at a language model
Alex Thorn, Head of Research at Galaxy Research, described the sweeps as likely "orchestrated with a large language model." It stands unverified. The claim is about execution at scale. Deriving candidate seeds and checking balances across thousands of addresses is repetitive work, and so is building the transactions that spend them. Coinkite chief executive Rodolfo Novak made a related point on 3 August, saying Coldcard's "code has always been publicly viewable" and suggesting an attacker had used automated tooling to find the flaw before researchers did. Novak and Thorn are separate parties; neither account confirms the other. Separately, the non-custodial swap service Boltz disabled its Bitcoin bridge indefinitely. Its statement, reported on 3 and 4 August, said "attackers now iterate faster than a team our size can find and patch vulnerabilities."
Tagged and unspent
Roughly 90% of the stolen bitcoin had not moved as of 4 August, and 100% of the coins taken in the first three waves were still in attacker-controlled addresses on Galaxy's accounting. The proceeds have not yet met an exchange, a mixer, or any counterparty willing to take them. Galaxy said it was passing attacker and victim addresses to US federal law enforcement, and to exchanges and compliance firms, which turns the unmoved balances into a tagged set. Tagged coins get harder to spend the longer they sit. Whether fifteen operators can stay that patient is a different question from whether one could.
Read also: Coinkite Tells Coldcard Users to Migrate as a Third Sweep Lands