Galaxy Research head Alex Thorn said 87.3% of the Bitcoin stolen in the Coldcard hardware wallet hack, 1,561 of 1,789.28 BTC, worth roughly $138.8 million at current prices, remains untouched in attacker-controlled addresses, according to an August 24, 2026 update on X.
Coldcard hack funds remain visible on the blockchain
The latest coldcard hack figures offer investigators something valuable: a substantial portion of the stolen Bitcoin remains visible onchain.
Galaxy said Bitcoin associated with the first three identified attack waves has remained unmoved.
That gives exchanges, compliance companies and law enforcement a continuing opportunity to monitor the attacker-controlled addresses and potentially intervene if the funds reach centralized platforms.
Galaxy has shared identified attacker addresses with relevant industry and investigative organizations.
The situation also demonstrates one of Bitcoin’s defining characteristics. Although criminals can attempt to obscure the trail, transactions remain permanently recorded on the blockchain, allowing researchers to reconstruct movements and identify relationships between wallets.
Coldcard hack victims lost long-held Bitcoin
The coldcard hack is particularly damaging because many affected coins had been dormant for years before being stolen.
Galaxy’s latest analysis found a median dormancy period of roughly 3.2 years among affected addresses, with an average of about 3.6 years.
The firm has also received 221 victim reports documenting 790.72 BTC in losses, equal to 44.2% of the total Bitcoin attributed to the attack.
The median reported loss was 1.04272 BTC, meaning more than half of the reported victims lost more than one Bitcoin.
That statistic makes the coldcard hack more than a headline-grabbing cryptocurrency theft; it represents substantial losses for long-term Bitcoin holders who believed they were relying on cold-storage security.
Coldcard hack attackers turn to CoinJoin and peel Chains
Not all Bitcoin linked to the coldcard hack has remained stationary.
Galaxy’s analysis shows that some funds from later attack waves have been moved using CoinJoin transactions, peel chains and other techniques intended to make blockchain tracing more difficult.
Galaxy previously reported that a portion of the stolen Bitcoin had entered CoinJoin transactions, while other funds continued moving through carefully structured onchain paths.
Thorn has emphasized that the movement of funds does not necessarily mean the attackers have successfully cashed out. Rather, blockchain investigators can continue following the transactions and flagging addresses as the Bitcoin travels through the ecosystem.
That distinction is crucial. A Bitcoin transaction can obscure ownership patterns without erasing the underlying transaction history.
Coldcard hack exposes risks of hardware-wallet security
The coldcard hack has also triggered broader questions about the security assumptions surrounding hardware wallets.
Galaxy previously explained that the incident stemmed from a historical firmware vulnerability affecting certain Coldcard devices.
The flaw involved faulty entropy generation during seed creation, potentially making some private keys significantly weaker than intended.
Galaxy advised users still holding funds on affected single-signature Coldcard wallets to move those assets to new addresses.
The research firm also said confirmed attacker activity had abated, although victim reports continued to increase the estimated losses.
The coldcard hack therefore carries a wider warning for the self-custody industry: physical isolation from the internet does not automatically protect assets if vulnerabilities exist in the software or cryptographic processes used to generate private keys.
Coldcard hack investigation still developing
The coldcard hack investigation remains active, and Galaxy’s numbers could continue changing as more victims identify losses and researchers establish additional links.
Importantly, there is no reliable evidence in the cited research connecting this incident to the unrelated claim that Inferno Drainer steals USDC.
The Galaxy analysis concerns Bitcoin stolen through the Coldcard vulnerability, and conflating the two would risk publishing inaccurate information.
For now, the clearest picture is stark: 1,789.28 BTC has been attributed to the coldcard hack, 1,561 BTC remains unmoved, and a large portion of the stolen fortune is still sitting where blockchain investigators can see it.
The coldcard hack may have delivered a devastating blow to thousands of Bitcoin holders, but the attackers have not erased the digital trail.
As long as the majority of the stolen Bitcoin remains dormant, investigators retain an important advantage: they know where much of the money is.