On-chain investigationBitcoin · Hardware wallets

The Coldcard wallet hack: $80M gone in 41 minutes

A flaw in a popular bitcoin wallet let thieves empty more than a thousand accounts in 41 minutes. Most of the money is still sitting where they left it, in plain sight. Nobody can touch it.

1,240BTC
stolen and traced in this analysis
≈$80m
at the price on the day of the theft
41
minutes from first sweep to last, 30 July
3,297
victim addresses emptied across four waves
94.8%
of it has never moved since

At 6:03 on the morning of Aug. 2, a payment of 294 satoshis left a bitcoin wallet. It was worth about two cents.

The person who owned the wallet noticed it later, after the rest of their money was gone, and drew the obvious conclusion. Someone had tested the route with a trivial amount before coming back for the real sum. Someone had been studying them. That is what a test payment means, and it is what they told the people helping them.

They were wrong, and the way they were wrong turns out to be the most revealing thing about the largest hardware-wallet theft on record.

That 294-satoshi payment was not a payment at all. It was one of 902 pieces of bitcoin pulled out of 795 different people's wallets, in different countries, by a single automated transaction that took less than a second to broadcast. Their two cents rode along with everyone else's. Three other victims in that same transaction happened to be holding exactly 294 satoshis themselves, leftovers from an unrelated spam campaign months earlier.

Nobody was watching them. A machine was harvesting a thousand strangers, and their wallet was on the list.

FIG 1One transaction, 902 inputs, 795 victims, and their two cents
Transaction d72e2d8e…8c89a4, 2 August 2026, 04:03:56 UTC. 902 inputs drawn from 795 distinct victim addresses into a single output of 64.90947964 BTC. Each strand is one input; strands are not sized, because per-input amounts are not shown here. The highlighted strand is the 294-satoshi input described above. Smallest input 0.00000294 BTC, largest 5.22556812 BTC; four inputs held exactly 294 satoshis.

Forty-one minutes

The theft began at 1:10 a.m. UTC on July 30 and the serious part was finished by 1:51.

In those 41 minutes, according to blockchain records analyzed for this article, three separate collection addresses swallowed the contents of 1,199 bitcoin addresses. The total was roughly 1,050 bitcoin, worth something close to $68 million at the time. The three collection addresses had been created that same night. Two of them existed for less than a quarter of an hour before being emptied into long-term storage and abandoned forever.

FIG 2Three collectors, running concurrently, 01:10:20 – 01:51:26 UTC
Each track begins when the collection address received its first bitcoin and ends when it was emptied. Track height is proportional to the bitcoin gathered. The three ran side by side and never paid each other. A fourth, minor collector contributed 104 victim addresses and 0.77324382 BTC and was emptied at 01:43:00; its first receipt is not established, so it is shown only as a point. Totals across the window: 1,199 victim addresses, 1,050.14 BTC.

The independent research firm Galaxy Research, working separately, put the first wave at 1,196 addresses and 1,082 bitcoin, figures that land within a fraction of a percent of the blockchain reconstruction. Galaxy has since estimated the full campaign at 1,596 bitcoin taken from about 7,300 addresses, and says the number could reach 2,055 if a suspected fourth wave is confirmed.

The cause was not a hack in any conventional sense. Nobody broke into a house, guessed a password or tricked anyone into clicking a link.

Coinkite, the Canadian company that makes the Coldcard hardware wallet, disclosed on July 30 that a build error dating to March 2021 had caused some of its devices to generate wallet seeds — the string of words that is, functionally, the money — using an ordinary software random number generator instead of the dedicated hardware one they were designed to use.

A properly generated seed is drawn from a pool of possibilities so large that the number has no useful physical comparison. The affected devices were drawing from a pool small enough to search. Coinkite's own analysis suggests seeds from one affected model may have had around 40 bits of randomness, against the 128 intended. The difference between those two numbers is not a matter of degree. One is unbreakable. The other is a weekend of computing.

“One is unbreakable. The other is a weekend of computing.”
FIG 3The collapse of the search space
Bar length is bits of entropy, which is a log scale: each step right doubles the number of possible seeds. A linear axis is impossible here; the values differ by twenty-six orders of magnitude. Figures are Coinkite's own disclosure.

Somebody, or several somebodies, simply generated the candidate seeds, calculated which bitcoin addresses each one would produce, and checked the public ledger to see which of those addresses had money in them. Then they waited, and swept them all at once.

Coinkite has said at least 15 separate attackers piled in once the flaw became known. The blockchain cannot distinguish one operator from several running identical software, and the first wave alone shows three collection chains running side by side that never touched each other.

FIG 4The whole campaign: thousands of victims, seven destinations
Ribbon thickness is proportional to bitcoin. Four waves between 30 July and 2 August. Six destinations have never made an outgoing payment; the seventh (the wave-3 sweep, which used no intermediate collector) was laundered on 4 August and is set apart.

Money you can see and cannot have

Here is what makes this theft different from almost every other: the money has not gone anywhere.

As of Aug. 7, roughly 1,176 bitcoin, about 95 percent of everything traced in this analysis, was sitting in six bitcoin addresses that have never made a single outgoing payment. Anyone with a web browser can look at them. Anyone can watch the balances. Nobody can do anything about it.

FIG 5Seven addresses, six of them untouched
Balances as of 7 August 2026. Six addresses have never made an outgoing payment. The seventh moved once, on 4 August, and its balance is now zero.

Screening against three commercial blockchain-intelligence databases returned no matches on any of those addresses: no exchange, no service, no previously known entity. They are new, anonymous, and inert.

This is the strange arithmetic of bitcoin theft. Stolen coins are perfectly visible and perfectly useless until the thief tries to convert them into something spendable, and that conversion almost always means passing through a business that has to ask who you are. Until then the money sits there, fully public and entirely out of reach, like cash sealed inside a glass case in a public square.

Which is why what happened on Aug. 4 matters.

“Like cash sealed inside a glass case in a public square.”

The rehearsal

That evening, at 19:56 UTC, a seventh address moved for the first time. It sent its entire balance of about 64.9 bitcoin to a brand-new address, in a transaction with one input and one output and a fee of 610 satoshis. Nothing was spent. The money simply changed seats.

Forty-six minutes later it went into a CoinJoin: a transaction with 324 inputs and 382 outputs, in which hundreds of unrelated people's coins are shuffled together so that no observer can say which output belongs to which input. The output sizes were the mathematically distinctive amounts used by one well-known mixing protocol.

From there, following the money became guesswork.

FIG 6Forty-six minutes, and then nothing
4 August 2026. A relocation that spent nothing, then a CoinJoin. The interval between them is the entire window in which the movement was still traceable.

Look at which pool they chose to launder first. The 64.9 bitcoin came from 795 victims and averaged about 0.08 bitcoin each: the smallest, most scattered holdings in the whole campaign, taken from the people least likely to have hired anyone or filed anything. The two largest hoards, 562 and 398 bitcoin, were left untouched.

That reads like a rehearsal. Test the escape route with the cargo nobody will chase.

FIG 7They laundered the pool with the smallest victims, not the most money
Each pool plotted by total holdings against the average taken per victim address. The laundered pool sits mid-range on total but near the floor on average per victim. Only the dust pool, 1,126 addresses at about 0.04 BTC each and the least valuable pool in the campaign, is lower. Every larger-per-victim pool was left alone.
“Test the escape route with the cargo nobody will chase.”

It also handed investigators the one useful thing they have: a signature. The two-step pattern, a quiet relocation and then a CoinJoin roughly three quarters of an hour later, is now known. If another of those addresses stirs, that first innocuous move is a 45-minute warning.

What it costs, beyond the money

The false conclusion described at the top of this piece is not one person's alone. Across this incident, victims are looking at tiny transactions in their records and reading them as evidence that someone close to them was involved. Business partners, family members, employees who helped set up a wallet years ago: all become suspects, because a two-cent payment looks personal in a way that a firmware bug does not.

The blockchain refutes it plainly. These coins were taken in transactions that simultaneously emptied hundreds of unrelated strangers. A person who knew one family and wanted their money would take that family's coins. They could not, in the same breath, rob 900 people they had never heard of.

The exploit required no access to anyone's home, devices or backups. The seed was computed from nothing, by someone who never knew the victim existed.

For the people affected, the practical advice is unforgiving. A seed generated by an affected device is permanently compromised, and no software update repairs it. The flaw is baked into the words themselves. Moving coins to fresh addresses inside the same wallet accomplishes nothing, because the thief can derive every address that wallet will ever produce. The only remedy is a new seed on fixed firmware, and moving everything to it.

Users who added 50 or more physical dice rolls when they first set up their device, or who protected their funds with an additional passphrase, were never exposed.

The six addresses are still there this morning. Balances unchanged, sitting in public, indexed by every block explorer on the internet.

Somewhere, someone is deciding when to move them. The last time that happened, there were 46 minutes of warning.

How this was reported

An address was counted as belonging to the thieves only where four things were true at once.

Findings come from a reconstruction of the public bitcoin ledger. An address qualified only if: it received its first ever payment on or after July 29, 2026; it was funded by many separate addresses; it paid out to no more than two destinations; and the payments into it drained their source addresses to exactly zero, leaving no change behind.

The third test is what separates thieves from businesses. Two addresses created during the same window handled 28,900 and 22,210 bitcoin and were excluded from the findings, because each paid out to more than 2,000 destinations, which is the behaviour of an exchange serving customers, not a collection point.

Applied to the first wave without reference to any published figure, the method identified 1,199 victim addresses and 1,050.14 bitcoin. Galaxy Research, working independently, reported 1,196 addresses and 1,082.65 bitcoin for the same wave.

This analysis accounts for about 78 percent of the total Galaxy Research attributes to the campaign. The remainder has not been traced and is not claimed here. The count refers to addresses, not people: one person can own hundreds of addresses, so the number of human victims is smaller and cannot be determined from the ledger.

Victim addresses are not published, to avoid exposing or identifying people who have been robbed.

Run this analysis yourself

Every figure in this piece came out of Bitquery’s blockchain data APIs, and our MCP server puts the same data inside your AI agent.

Point Claude, Cursor or any MCP client at Bitquery MCP and ask it to trace a sweep, cluster a collector, or watch an address for its first outgoing payment. 40+ chains, 1PB+ of indexed data, and no pipeline to build. Or hand the whole case to Bitquery AI Investigations, the agent that traces funds, attributes wallets, and writes auditable reports.

Evidence appendix

Check the work

Every address and transaction below links to the Bitquery Bitcoin explorer so readers can verify independently. No victim address is published. Balances as of 7 August 2026 and may have changed since publication.

Where the money is

Seven destination addresses, largest first.

#AddressHolds (BTC)StatusVictim addresses

Total still unspent, six addresses: 1,175.51326772 BTC

Collection addresses

Each existed only long enough to gather victim funds, then was emptied and never used again.

AddressFeedsCreated (UTC)Victim addresses

Key transactions

Date (UTC)Transaction IDBTCInputsWhat it shows

Run the next investigation in minutes

Ask any question of the blockchain. Bitquery's AI Investigations agent traces funds, attributes wallets, and writes auditable reports across every major chain.

Explore AI Investigations
Bitquery Research · On-chain investigation · 7 August 2026 Figures marked as Galaxy Research or Coinkite are theirs; all ledger reconstruction is our own.