Galaxy Research: Coldcard Hack Losses Reach 1,789 BTC, Most Funds Still Unmoved

banner-image

Analysts estimate roughly 87% of the stolen bitcoin, worth about $114 million, has not been moved since the breach

Galaxy Research has published an estimate placing total losses from a hack involving Coldcard hardware wallets at 1,789 BTC. The figure represents one of the more detailed accounting attempts of the incident to date, according to the firm's findings.

According to Galaxy's analysis, about 87% of the stolen bitcoin has not moved since the theft occurred. That portion works out to roughly 1,561 BTC sitting in wallets linked to the attackers. The remaining balance, around 228 BTC, appears to have already been transferred or liquidated in some form.

The total value of the stolen funds was estimated at approximately $114 million, based on bitcoin prices at the time of reporting. Coldcard is a hardware wallet product designed for cold storage of bitcoin, marketed specifically toward users seeking to keep private keys offline and away from internet-connected devices.

Hardware wallets are generally considered a stronger security option than software-based or exchange-hosted custody. A breach affecting a device built for that purpose raises questions about how the theft occurred, though the specific attack vector was not detailed in Galaxy's figures. The scale of losses, if confirmed, would rank among the larger hardware-wallet-related incidents reported in recent memory.

The fact that most of the stolen bitcoin remains unmoved is notable from a tracking and recovery standpoint. Blockchain analysts often watch for movement of stolen funds as an early signal of laundering attempts, whether through mixers, cross-chain bridges, or exchange deposits. Static wallets can indicate that attackers are waiting for scrutiny to fade, or that the funds are being held for other strategic reasons.

Galaxy's research did not specify whether law enforcement or the wallet manufacturer had been formally notified of the breach, nor did it detail any planned response from Coldcard's developers. The origin of the compromise, whether tied to a firmware vulnerability, a supply chain issue, or a targeted attack on specific users, was not addressed in the available figures. Additional technical disclosures from the company or independent security researchers would likely be needed to clarify how the breach was carried out.

Market Impact

A theft of this size, even if not immediately liquidated, adds a notable amount of bitcoin to the pool of coins with a known illicit history. Should the unmoved 1,561 BTC eventually enter circulation through exchanges or over-the-counter channels, it could draw scrutiny from compliance teams and blockchain forensic firms tracking tainted addresses.

The incident may also renew attention on hardware wallet security more broadly, particularly for users and institutions relying on cold storage as a primary defense against theft. Any confirmed vulnerability in a widely used hardware wallet could prompt firmware updates, device recalls, or shifts in custody practices among bitcoin holders who prioritize self-custody.

As blockchain analysts continue tracking the unmoved bitcoin, further clarity on the cause of the breach and any recovery efforts will likely depend on additional disclosures from Coldcard and independent security researchers.

Frequently Asked Questions

What is Coldcard?

Coldcard is a hardware wallet designed for storing bitcoin offline, intended to protect private keys from internet-based attacks.

How much bitcoin was stolen in the hack?

Galaxy Research estimated total losses at 1,789 BTC, valued at approximately $114 million at the time of the report.

What does it mean that 87% of the stolen bitcoin is unmoved?

It means roughly 1,561 BTC remains in wallets linked to the attackers without being transferred, sold, or laundered so far, based on blockchain tracking.

Has the cause of the breach been confirmed?

The specific method used to carry out the hack, such as a firmware flaw or targeted attack, was not detailed in the available reporting.