We Verified the Coldcard Hacker's Laundering Offer Ourselves. Here's What 'Public' Actually Means Here.
Coldcard's entropy flaw is no longer a single 594 BTC wave: Galaxy Research confirms 1,596 BTC — about 2,055 if you count a fourth wave still unconfirmed — and at least fifteen separate attackers working the same flaw independently. One of them already received a laundering offer directly on-chain, which we verified ourselves against mempool.space.
When we published the technical breakdown of Coldcard's entropy flaw, the number was 594 BTC in one wave. Four days later, the case looks nothing like what we described: four waves, likely several distinct attacker groups, and a laundering offer sent directly to one of the attacker's addresses, in plain sight of anyone who knows where to look.
The escalation, in verified numbers
Per Galaxy Research's tracking, Wave 1 (the one we covered) took roughly $30 million in its first ten minutes, targeting the largest wallets first. Waves 2 and 3 followed, then a Wave 4 that swept roughly 449 BTC more.
As of August 4, Galaxy's count reads like this — and it repays reading carefully, because most headlines merge two numbers that are not the same thing:
- Confirmed: 1,596 BTC (north of $100 million) taken from roughly 7,300 addresses, across three confirmed waves plus fourteen smaller incidents. That figure rests on victim reports and on-chain analysis.
- Including the suspected: about 2,055 BTC (~$130 million) and more than 7,700 addresses, once Wave 4 is added in.
That gap is not a rounding quibble. Galaxy deliberately keeps Wave 4 out of its headline number: it reports "medium-high confidence" that the wave is an attacker's work, but no victim has confirmed it yet. We keep the same separation, for the same reason they do — an unconfirmed number published as though it were confirmed is precisely the kind of figure nobody goes back and corrects.
What has changed qualitatively is the number of actors involved: Galaxy now counts at least fifteen independent attackers working the same flaw separately.
Why this probably isn't one attacker
Here's the nuance most coverage flattens into a single villain narrative. Galaxy Research doesn't talk about "the attacker" in the singular; it explicitly warns that Wave 3 shouldn't be assumed to share an operator with Waves 1 and 2, because the transaction structuring differs. Their read is that Coldcard's vulnerable key space has effectively become open hunting ground, with multiple groups racing across it independently, no coordination involved. Coinkite, for its part, had CEO Rodolfo Novak acknowledge the company had no idea the bug existed until outside researchers surfaced it.
The laundering offer, checked by us, not taken on faith
We didn't take third-party coverage at its word for this one — we checked it ourselves. The transaction is confirmed in block 960,549, dated August 1, 2026, and its OP_RETURN output carries a direct offer to "clean" bitcoin, help with KYC, and cash out, for a 10% cut, with a Telegram handle attached (we're deliberately not reproducing it here). Who sent it remains unconfirmed — coverage elsewhere speculates it could be a real laundering operation, or a trap set by law enforcement.
Verified directly against mempool.space, not a secondary source: the transaction exists, it's confirmed, and the message matches what's been reported. Same verification discipline we apply to every figure we publish.
Why "identified" doesn't mean "caught"
This is the part that connects directly to what we do at NodeWitness. A public, visible attacker address doesn't mean that attacker can be stopped: anyone can message it, watch its balance, track its movements — none of that identifies the actual person behind it, unless those funds eventually touch a service with real KYC, not an anonymous Telegram offer. It's the same principle covered in our guide on whether your own wallet is traceable: the chain is a public ledger, but a public ledger only identifies someone the moment they make the mistake of linking an address to their real identity.
Update, August 6: TRM's higher count, a second laundering offer, and two pieces of context
TRM Labs, in its own writeup published August 4, counts the damage somewhat differently than Galaxy: 1,816 BTC (~$116 million) from more than 5,200 addresses, across the same four waves. The gap with Galaxy's figure above isn't an error on either side — it's the same reason the very first estimate of this case (roughly $38 million, from Lookonchain on July 30) already diverged from everything that followed: each firm applies its own methodology (on-chain behavioral pattern-matching versus case-by-case confirmation) and makes its own call on which waves count toward the headline number. There's no single "correct" figure today, only figures with their own stated method — worth citing with the source attached, not treated as interchangeable.
TRM also confirms something we could previously only infer: the funds are still mostly sitting untouched, consolidated into a small number of addresses. The one real exception as of their report: a 64.9 BTC deposit to Wasabi (a CoinJoin coordinator) and 200 ETH to Tornado Cash, both on August 4 — a single hop, not an active laundering pattern yet.
A second laundering offer, distinct from the one we already verified. We went back to the same address we'd already investigated — against mempool.space, no reliance on third-party coverage — and found a second OP_RETURN message, repeated five times between August 3 and 5: "BTC To XMR at 7%. No waiting time," with a different Telegram contact than the first offer. This isn't the same offer with a different number attached: they're two separate pitches (one promising to "clean" bitcoin with fake KYC for 10%, the other offering a direct swap to Monero for 7%), from different senders — and the one we covered on August 1 remains, by two full days, the earlier of the two.
Two pieces of context we checked separately. Coinkite officially confirms TAPSIGNER, OPENDIME, and SATSCARD — other key-signing and custody devices from the same maker — are unaffected: they run on a different codebase entirely, unrelated to Coldcard's flaw. And this isn't the first flaw of this kind this year: in July, security firm Coinspect's "Ill Bloom" research found an equally weak random number generator in several older mobile software wallets (not hardware), with more than $5 million already stolen since May. Different manufacturers, different product category — but the pattern itself, silent weak randomness with no visible symptom until someone steals from it, is no longer a one-off.
If your Coldcard is affected
If you haven't migrated yet, the urgency hasn't dropped, it's gone up. With multiple groups working the same vulnerable key space in parallel and no sign it's exhausted, every day a compromised seed stays active is another day of real exposure. The full migration plan, with exact priority order by model, is still in the original article, unchanged.
You can investigate any Bitcoin address — including the ones in this case, if you want to follow the trail — with our address analyzer, free, against our own node.
Last updated: August 6, 2026