Galaxy Research: Coldcard Hack Losses Total 1,789 BTC, 87% of Stolen Funds Still Unmoved

Over half of 221 verified victim reports exceeded losses of 1 Bitcoin, highlighting growing risks in hardware wallet security

edit
By LineZotpaper
Published
Read Time2 min
Galaxy Research has tallied losses from the recent Coldcard hardware wallet hack at 1,789 Bitcoin, with 87% of the stolen funds remaining unmoved as of August 25, 2026. The firm analyzed 221 verified victim reports, finding that more than half of those affected lost over 1 Bitcoin each, underscoring the financial impact of the breach on individual holders.

The hack, which targeted users of Coldcard — a popular hardware wallet made by Coinkite — has emerged as one of the larger cryptocurrency theft incidents of 2026. Galaxy Research’s tally, published Monday, provides the most detailed public accounting of losses so far. The report states that of the 221 confirmed victim reports, a “significant majority” reported losses exceeding 1 BTC, though the precise distribution was not disclosed.

Coldcard wallets are widely used by Bitcoin maximalists and security-conscious investors because of their air-gapped design and open-source firmware. However, the breach appears to have exploited vulnerabilities in the supply chain or firmware update process, though Coinkite has not issued a public forensic report as of press time. Galaxy Research’s numbers suggest that the attackers managed to compromise wallets across multiple batches, potentially through a targeted seed-phrase interception or a malicious firmware upgrade.

The fact that 87% of the stolen Bitcoin — worth roughly $115 million at current prices — has not been moved has led analysts to believe the attackers may be holding out in hopes of avoiding detection, or that they were unable to immediately liquidate such large sums. Alternatively, the funds could be stored in cold storage by the hackers themselves, waiting for a favorable market or better laundering opportunities.

Victims have taken to social media to express frustration, with some claiming that Coinkite’s response has been slow. Coinkite representatives have not commented on Galaxy’s findings but have previously stated that they are cooperating with law enforcement. The incident has reignited debate about the security of hardware wallets, which are often promoted as the safest method for storing cryptocurrency.

The crypto community is watching for further updates, particularly any movement from the unidentified wallets holding the bulk of the stolen funds. Galaxy Research noted that it will continue monitoring the situation.

§

Analysis

Why This Matters

  • The hack highlights that even hardware wallets, long considered the gold standard for secure crypto storage, are not immune to sophisticated attacks. For individual investors, this means reassessing storage strategies and being vigilant about firmware updates.
  • With 87% of stolen BTC unmoved, the potential for a large sell-order exists, which could temporarily depress Bitcoin prices if the hackers ever decide to cash out.
  • The incident is likely to prompt increased scrutiny of hardware wallet manufacturers’ supply chain security and update mechanisms, potentially leading to industry-wide standards.

Background

Coldcard, produced by Canadian company Coinkite, has a reputation as a high-security hardware wallet favored by Bitcoin maximalists. It supports air-gapped transactions via microSD cards and is open source. The breach was first reported in early August 2026 when users found their wallets drained. Initial reports suggested a firmware vulnerability; later theories pointed to a supply chain attack where tampered devices were shipped directly to customers. Galaxy Research began its investigation shortly after, collecting reports from affected users through a public form. The 1,789 BTC figure is the most comprehensive estimate to date. Previously, Coinkite had not disclosed the total losses. The hack is reminiscent of the 2020 Ledger data breach, though that incident exposed personal information rather than directly stealing funds.

Key Perspectives

Galaxy Research: The firm emphasizes transparency and has called on Coinkite to release a full post-mortem. Its data suggests a coordinated attack on a specific firmware version. Galaxy notes that 87% unmoved is unusually high and may indicate the hackers are still planning their exit. Coldcard users: Many victims express frustration over what they perceive as insufficient support and communication from Coinkite. Some have filed police reports and are pushing for reimbursement or a compensation fund. Others warn that trust in the Coldcard brand has been severely damaged. Security experts: Some argue that hardware wallets should always be purchased directly from the manufacturer and that users must verify firmware hashes before updating. Others point out that no hardware solution can protect against a compromised supply chain. The incident underscores the need for multi-sig setups and better user education.

What to Watch

  • Movement of the stolen 1,789 BTC from the identified hacker wallets — any transfer activity could signal an imminent sell-off.
  • Coinkite’s official response: whether it issues a detailed forensic report, acknowledges liability, or offers compensation.
  • Regulatory attention: lawmakers may scrutinize hardware wallet security standards and consumer protections in the crypto space.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.