Galaxy Puts the Coldcard Theft at 1,719 BTC From More Than 250 Victims

Galaxy Research has put a firmer number on the Coldcard theft. The firm's analysis counts 1,719 BTC confirmed stolen, roughly $111 million, taken from more than 250 victims by at least 15 distinct attackers. Galaxy warns the total may yet top $130 million once suspected activity is included. The release itself is dated two ways. Crypto Briefing carries the report as 7 August, The Crypto Times as 8 August, and nothing in the coverage settles the difference; we treat it as landing across the two days.
The report is the fullest accounting yet of the entropy flaw, a weakness in the randomness used to generate private keys, that has been draining Coldcard hardware wallets since 30 July. This site has followed the exploit since the first 594 BTC sweep, and the new figures roughly triple that opening tally.
How the count moved
The numbers climbed in steps. The first sweep took 594 BTC at the end of July. Further sweeps followed within days, and by 4 August Galaxy's preliminary count had losses near $100 million with at least fifteen attackers behind them. The new report firms the confirmed figure at 1,719 BTC across at least three waves, cross-checked against the victim reports collected by the researcher posting as @intangiblecoins. Those reports now number more than 250.
Not every tally agrees. One tracker gives a confirmed range of 1,596 to 1,719 BTC, or $100 million to $111 million, depending on the confirmation threshold applied. The counts do not fully reconcile. This article uses Galaxy's confirmed figure, the higher of the two.
Everyday victims, organized attackers
Galaxy's reading of the victim reports is blunt: the losses fell on "primarily everyday bitcoin users rather than large holders." The attacker side looks anything but casual. The firm identifies more than 25 separate attack patterns and at least 15 distinct threat actors, and it concludes the exploitation was coordinated, not a case of many parties independently finding the same flaw.
The flaw was "likely shared or sold before public announcement," Galaxy's analysts wrote.
That reading matters. A vulnerability that circulated privately before disclosure means the first sweeps were ahead of the public warnings, not behind them, and it changes how the earlier waves should be read: as one operation with many hands, not a scramble that started when the news broke.
Where $130 million comes from
The $111 million figure is what Galaxy can confirm on-chain. The $130 million ceiling rests on suspected activity, the largest piece a possible fourth wave of about 389 BTC on 3 August. Galaxy had not verified that wave at the time of the report. It is suspicion, not a count, and the firm labels it that way.
Most of the coins have not moved
The majority of the stolen bitcoin remained unspent on-chain when the report was compiled. That is an observable fact and only that; it says nothing about the attackers' plans. It does leave a window. Unspent coins can be watched, flagged and, at exchange doors, frozen. With victim reports still arriving and the suspected total running ahead of the confirmed one, the next number that matters is probably not another revision of the tally. It is the first large movement of the 1,719.
Read also: Coinkite Tells Coldcard Users to Migrate as a Third Sweep Lands