$130M Coldcard Heist: 90% of Stolen Bitcoin Hasn't Moved, and That's the Scary Part

The attackers aren't spending the Bitcoin, and that tells you everything about how patient, and dangerous, this operation really is.

Galaxy Research has confirmed three distinct attack waves targeting Coldcard hardware wallets, with losses already surpassing $100 million in Bitcoin. Investigators are now examining a suspected fourth wave that could push total losses to $130 million. Of everything stolen across the confirmed attacks, roughly 90% remains completely untouched on-chain.

Why the Silence Is Louder Than the Theft

When hackers steal crypto and don't move it, one of two things is happening. Either they're waiting for chain analysis heat to cool, or they're operating with a level of discipline that suggests a highly coordinated, professional operation, not opportunistic thieves.

Neither scenario is comforting for Coldcard users.

The three confirmed waves represent a sustained, methodical campaign rather than a one-time breach. The suspected fourth wave, still under active investigation, suggests the attack vector hasn't been fully closed. Galaxy Research has not disclosed the specific method used to compromise wallets, which means affected users may not know they're exposed.

What We Know About the Attack Pattern

Galaxy's report frames this as a multi-wave operation, meaning the same vulnerability or technique was deployed repeatedly across separate timeframes. This isn't a single exchange hack or a smart contract exploit. These are cold wallets, devices specifically purchased to keep Bitcoin offline and theoretically untouchable.

The fact that Coldcard specifically is at the center of these confirmed waves matters. Coldcard is widely regarded as one of the most security-hardened Bitcoin hardware wallets on the market, popular with self-custody maximalists who hold significant amounts. The target profile here skews toward serious, long-term holders, not casual users.

The $130M Question Nobody Can Answer Yet

Investigators have not publicly confirmed how the wallets were compromised. Supply chain attacks, firmware vulnerabilities, and seed phrase interception are all possibilities being examined across the broader hardware wallet industry. Until Galaxy or Coldcard's manufacturer, Coinkite, provides a confirmed attack vector, affected users are flying blind.

The 90% of unmoved Bitcoin creates an unusual on-chain surveillance opportunity. Chain analysts are almost certainly watching those addresses in real time. The moment funds move, it becomes a high-profile tracking event.

What Crypto Holders Should Do Right Now

If you hold Bitcoin on a Coldcard, especially one purchased through a third-party retailer or received as a gift, verify firmware integrity immediately using Coldcard's official documentation. Check whether your device's purchase timeline overlaps with any of the three confirmed attack waves once Galaxy releases additional details.

Watch for an official statement from Coinkite. If a fourth wave is confirmed, the disclosure timeline and response will signal whether this vulnerability is contained or still active.

Self-custody isn't dead. But this story is a brutal reminder that hardware security is only as strong as the supply chain, firmware, and setup process behind it.