At 6:03 on the morning of Aug. 2, a payment of 294 satoshis left a bitcoin wallet. It was worth about two cents.
The person who owned the wallet noticed it later, after the rest of their money was gone, and drew the obvious conclusion. Someone had tested the route with a trivial amount before coming back for the real sum. Someone had been studying them. That is what a test payment means, and it is what they told the people helping them.
They were wrong, and the way they were wrong turns out to be the most revealing thing about the largest hardware-wallet theft on record.
That 294-satoshi payment was not a payment at all. It was one of 902 pieces of bitcoin pulled out of 795 different people's wallets, in different countries, by a single automated transaction that took less than a second to broadcast. Their two cents rode along with everyone else's. Three other victims in that same transaction happened to be holding exactly 294 satoshis themselves, leftovers from an unrelated spam campaign months earlier.
Nobody was watching them. A machine was harvesting a thousand strangers, and their wallet was on the list.
Forty-one minutes
The theft began at 1:10 a.m. UTC on July 30 and the serious part was finished by 1:51.
In those 41 minutes, according to blockchain records analyzed for this article, three separate collection addresses swallowed the contents of 1,199 bitcoin addresses. The total was roughly 1,050 bitcoin, worth something close to $68 million at the time. The three collection addresses had been created that same night. Two of them existed for less than a quarter of an hour before being emptied into long-term storage and abandoned forever.
The independent research firm Galaxy Research, working separately, put the first wave at 1,196 addresses and 1,082 bitcoin, figures that land within a fraction of a percent of the blockchain reconstruction. Galaxy has since estimated the full campaign at 1,596 bitcoin taken from about 7,300 addresses, and says the number could reach 2,055 if a suspected fourth wave is confirmed.
The cause was not a hack in any conventional sense. Nobody broke into a house, guessed a password or tricked anyone into clicking a link.
Coinkite, the Canadian company that makes the Coldcard hardware wallet, disclosed on July 30 that a build error dating to March 2021 had caused some of its devices to generate wallet seeds — the string of words that is, functionally, the money — using an ordinary software random number generator instead of the dedicated hardware one they were designed to use.
A properly generated seed is drawn from a pool of possibilities so large that the number has no useful physical comparison. The affected devices were drawing from a pool small enough to search. Coinkite's own analysis suggests seeds from one affected model may have had around 40 bits of randomness, against the 128 intended. The difference between those two numbers is not a matter of degree. One is unbreakable. The other is a weekend of computing.
“One is unbreakable. The other is a weekend of computing.”
Somebody, or several somebodies, simply generated the candidate seeds, calculated which bitcoin addresses each one would produce, and checked the public ledger to see which of those addresses had money in them. Then they waited, and swept them all at once.
Coinkite has said at least 15 separate attackers piled in once the flaw became known. The blockchain cannot distinguish one operator from several running identical software, and the first wave alone shows three collection chains running side by side that never touched each other.
Money you can see and cannot have
Here is what makes this theft different from almost every other: the money has not gone anywhere.
As of Aug. 7, roughly 1,176 bitcoin, about 95 percent of everything traced in this analysis, was sitting in six bitcoin addresses that have never made a single outgoing payment. Anyone with a web browser can look at them. Anyone can watch the balances. Nobody can do anything about it.
Screening against three commercial blockchain-intelligence databases returned no matches on any of those addresses: no exchange, no service, no previously known entity. They are new, anonymous, and inert.
This is the strange arithmetic of bitcoin theft. Stolen coins are perfectly visible and perfectly useless until the thief tries to convert them into something spendable, and that conversion almost always means passing through a business that has to ask who you are. Until then the money sits there, fully public and entirely out of reach, like cash sealed inside a glass case in a public square.
Which is why what happened on Aug. 4 matters.
“Like cash sealed inside a glass case in a public square.”
The rehearsal
That evening, at 19:56 UTC, a seventh address moved for the first time. It sent its entire balance of about 64.9 bitcoin to a brand-new address, in a transaction with one input and one output and a fee of 610 satoshis. Nothing was spent. The money simply changed seats.
Forty-six minutes later it went into a CoinJoin: a transaction with 324 inputs and 382 outputs, in which hundreds of unrelated people's coins are shuffled together so that no observer can say which output belongs to which input. The output sizes were the mathematically distinctive amounts used by one well-known mixing protocol.
From there, following the money became guesswork.
Look at which pool they chose to launder first. The 64.9 bitcoin came from 795 victims and averaged about 0.08 bitcoin each: the smallest, most scattered holdings in the whole campaign, taken from the people least likely to have hired anyone or filed anything. The two largest hoards, 562 and 398 bitcoin, were left untouched.
That reads like a rehearsal. Test the escape route with the cargo nobody will chase.
“Test the escape route with the cargo nobody will chase.”
It also handed investigators the one useful thing they have: a signature. The two-step pattern, a quiet relocation and then a CoinJoin roughly three quarters of an hour later, is now known. If another of those addresses stirs, that first innocuous move is a 45-minute warning.
What it costs, beyond the money
The false conclusion described at the top of this piece is not one person's alone. Across this incident, victims are looking at tiny transactions in their records and reading them as evidence that someone close to them was involved. Business partners, family members, employees who helped set up a wallet years ago: all become suspects, because a two-cent payment looks personal in a way that a firmware bug does not.
The blockchain refutes it plainly. These coins were taken in transactions that simultaneously emptied hundreds of unrelated strangers. A person who knew one family and wanted their money would take that family's coins. They could not, in the same breath, rob 900 people they had never heard of.
The exploit required no access to anyone's home, devices or backups. The seed was computed from nothing, by someone who never knew the victim existed.
For the people affected, the practical advice is unforgiving. A seed generated by an affected device is permanently compromised, and no software update repairs it. The flaw is baked into the words themselves. Moving coins to fresh addresses inside the same wallet accomplishes nothing, because the thief can derive every address that wallet will ever produce. The only remedy is a new seed on fixed firmware, and moving everything to it.
Users who added 50 or more physical dice rolls when they first set up their device, or who protected their funds with an additional passphrase, were never exposed.
The six addresses are still there this morning. Balances unchanged, sitting in public, indexed by every block explorer on the internet.
Somewhere, someone is deciding when to move them. The last time that happened, there were 46 minutes of warning.
An address was counted as belonging to the thieves only where four things were true at once.
Findings come from a reconstruction of the public bitcoin ledger. An address qualified only if: it received its first ever payment on or after July 29, 2026; it was funded by many separate addresses; it paid out to no more than two destinations; and the payments into it drained their source addresses to exactly zero, leaving no change behind.
The third test is what separates thieves from businesses. Two addresses created during the same window handled 28,900 and 22,210 bitcoin and were excluded from the findings, because each paid out to more than 2,000 destinations, which is the behaviour of an exchange serving customers, not a collection point.
Applied to the first wave without reference to any published figure, the method identified 1,199 victim addresses and 1,050.14 bitcoin. Galaxy Research, working independently, reported 1,196 addresses and 1,082.65 bitcoin for the same wave.
This analysis accounts for about 78 percent of the total Galaxy Research attributes to the campaign. The remainder has not been traced and is not claimed here. The count refers to addresses, not people: one person can own hundreds of addresses, so the number of human victims is smaller and cannot be determined from the ledger.
Victim addresses are not published, to avoid exposing or identifying people who have been robbed.
Every figure in this piece came out of Bitquery’s blockchain data APIs, and our MCP server puts the same data inside your AI agent.
Point Claude, Cursor or any MCP client at Bitquery MCP and ask it to trace a sweep, cluster a collector, or watch an address for its first outgoing payment. 40+ chains, 1PB+ of indexed data, and no pipeline to build. Or hand the whole case to Bitquery AI Investigations, the agent that traces funds, attributes wallets, and writes auditable reports.
Check the work
Every address and transaction below links to the Bitquery Bitcoin explorer so readers can verify independently. No victim address is published. Balances as of 7 August 2026 and may have changed since publication.
Where the money is
Seven destination addresses, largest first.
| # | Address | Holds (BTC) | Status | Victim addresses |
|---|
Total still unspent, six addresses: 1,175.51326772 BTC
Collection addresses
Each existed only long enough to gather victim funds, then was emptied and never used again.
| Address | Feeds | Created (UTC) | Victim addresses |
|---|
Key transactions
| Date (UTC) | Transaction ID | BTC | Inputs | What it shows |
|---|
Run the next investigation in minutes
Ask any question of the blockchain. Bitquery's AI Investigations agent traces funds, attributes wallets, and writes auditable reports across every major chain.
Explore AI Investigations