ChainThink reports that, as of August 14, Galaxy Research disclosed on X that over 1,778 BTC stolen due to a vulnerability in Coldcard hardware wallets have been identified, valued at approximately $112 million, with the final loss figure expected to rise further.
As of now, no new attacks have been confirmed since August 6. The attacker systematically reconstructed mnemonic phrases generated by Coldcard and transferred funds starting at least from the early hours of July 30.
Galaxy Research has tracked three major attack waves, over 30 smaller attack traces, and, combined with reports from more than 190 victims, has identified at least 33 additional attacker traces, confirming the presence of multiple attackers in the threat environment.
Of the stolen funds, 1,531 BTC remain in the attacker-controlled addresses, while approximately 246 BTC have been transferred, with 65% flowing into CoinJoin transactions and 35% further moved through methods such as chain stripping.
Galaxy Research has provided a list of the attacker's addresses to cryptocurrency exchanges, compliance investigators, and law enforcement agencies, and recommends that users still using single-signature Coldcard wallets transfer their funds to new addresses as soon as possible.

