A golden Bitcoin coin at the center with multiple thin beams of light converging from different directions at once, like signals arriving from several separate sources
Original illustration generated with AI (Adobe Firefly) — not representative of real data.

We Verified the Coldcard Hacker's Laundering Offer Ourselves. Here's What 'Public' Actually Means Here.

Coldcard's entropy flaw is no longer a single 594 BTC wave: it's four, roughly 1,816 BTC combined, and likely several distinct attackers exploiting the same flaw independently. One of them already received a laundering offer directly on-chain, which we verified ourselves against mempool.space.

When we published the technical breakdown of Coldcard's entropy flaw, the number was 594 BTC in one wave. Four days later, the case looks nothing like what we described: four waves, likely several distinct attacker groups, and a laundering offer sent directly to one of the attacker's addresses, in plain sight of anyone who knows where to look.

The escalation, in verified numbers

Per Galaxy Research's tracking, Wave 1 (the one we covered) took roughly $30 million in its first ten minutes, targeting the largest wallets first. Waves 2 and 3 followed, bringing the running total to roughly 1,367 BTC (~$88.6 million) by August 2. Wave 4, revised after correction, added roughly 449 more BTC across 709 additional addresses, with disclosure still ongoing as we write this. The cumulative total sits around 1,816 BTC, roughly $115 million.

Why this probably isn't one attacker

Diagram of a Bitcoin address receiving messages from several different observers at once: investigators, exchanges, curious onlookers, and other attackers — illustrating that an on-chain message is public to everyone equally
Original diagram: any message sent to a public address is visible to everyone, at the same time, with no exceptions.

Here's the nuance most coverage flattens into a single villain narrative. Galaxy Research doesn't talk about "the attacker" in the singular; it explicitly warns that Wave 3 shouldn't be assumed to share an operator with Waves 1 and 2, because the transaction structuring differs. Their read is that Coldcard's vulnerable key space has effectively become open hunting ground, with multiple groups racing across it independently, no coordination involved. Coinkite, for its part, had CEO Rodolfo Novak acknowledge the company had no idea the bug existed until outside researchers surfaced it.

The laundering offer, checked by us, not taken on faith

We didn't take third-party coverage at its word for this one — we checked it ourselves. The transaction is confirmed in block 960,549, dated August 1, 2026, and its OP_RETURN output carries a direct offer to "clean" bitcoin, help with KYC, and cash out, for a 10% cut, with a Telegram handle attached (we're deliberately not reproducing it here). Who sent it remains unconfirmed — coverage elsewhere speculates it could be a real laundering operation, or a trap set by law enforcement.

Verified directly against mempool.space, not a secondary source: the transaction exists, it's confirmed, and the message matches what's been reported. Same verification discipline we apply to every figure we publish.

Why "identified" doesn't mean "caught"

This is the part that connects directly to what we do at NodeWitness. A public, visible attacker address doesn't mean that attacker can be stopped: anyone can message it, watch its balance, track its movements — none of that identifies the actual person behind it, unless those funds eventually touch a service with real KYC, not an anonymous Telegram offer. It's the same principle covered in our guide on whether your own wallet is traceable: the chain is a public ledger, but a public ledger only identifies someone the moment they make the mistake of linking an address to their real identity.

If your Coldcard is affected

If you haven't migrated yet, the urgency hasn't dropped, it's gone up. With multiple groups working the same vulnerable key space in parallel and no sign it's exhausted, every day a compromised seed stays active is another day of real exposure. The full migration plan, with exact priority order by model, is still in the original article, unchanged.

You can investigate any Bitcoin address — including the ones in this case, if you want to follow the trail — with our address analyzer, free, against our own node.

Last updated: 2026-08-03