Skip to content
Active Currencies: 18,106
Market Cap: $2.254T
Bitcoin Dominance: 56.26%
24h Market Cap Change: $0.33

Coldcard exploit now hits 4,585 wallets – Attacker still holds $88.6M stolen BTC

The suspected Coldcard exploit continued expanding as investigators link more wallets and Bitcoin to the broader attack.

Coldcard exploit grows to 1,367 BTC as On-Chain tracking expands

The Coldcard exploit continues expanding as investigators uncover more affected wallets and stolen Bitcoin.

A recent discovery by Galaxy Research now links the incident to 4,585 addresses drained across three waves, totaling 1,367.05 BTC worth about $88.6 million.

The latest wave alone drained 207.73 BTC from 1,912 addresses, extending earlier estimates of 2,673 wallets and 1,158.81 BTC. More importantly, investigators found the stolen Bitcoin [BTC] remains 100% unspent, indicating the attacker prefers consolidation over immediate liquidation.

Source: Galaxy Research

That behavior suggests operational planning rather than opportunistic selling, leaving the funds ready for future movement. As the investigation progresses, additional linked addresses may emerge, further expanding the suspected scale and timeline of the exploit.

Post-exploit Bitcoin movements

That broader investigation now offers clearer insight into the attacker’s strategy after the initial theft. Onchain Lens shows the exploit cluster received 1,159.42 BTC, worth about $72.71 million, from 870 compromised addresses before consolidating the funds into eight verified wallets.

Source: On Chain Lens

However, the attacker has moved only 0.06 BTC to a fresh address, leaving roughly 1,159.35 BTC untouched.

Rather than signaling immediate liquidation, this pattern suggests the attacker is prioritizing control, organization, and reducing exposure before attempting larger transfers.

It also keeps most stolen Bitcoin visible on-chain, allowing investigators to monitor future movements.

Nevertheless, once funds begin leaving these clusters more frequently, the likelihood of laundering or broader distribution would increase significantly.

Can blockchain tracking keep up?

Although the attacker has not begun broader distribution, the investigation now enters a more decisive phase. Future on-chain movements will reveal whether the operation shifts from fund management to fund extraction.

Transfers to regulated exchanges could expose identities through KYC procedures, creating opportunities for intervention.

In contrast, movements through mixers or cross-chain bridges would fragment the transaction trail and complicate blockchain analysis.

Transaction frequency, address clustering, and routing patterns will therefore become more important than balance size alone. Continued inactivity would preserve clear investigative leads and strengthen monitoring efforts.

However, coordinated outbound transfers would mark the transition from a contained incident into a far more complex tracing challenge.


Final Summary

  • The suspected Coldcard exploit continues expanding as investigators link more wallets to the stolen BTC.
  • Future Bitcoin movements will determine how effectively investigators can continue tracking the stolen funds.
Disclaimer: AMBCrypto's content is meant to be informational in nature and should not be interpreted as investment advice. Trading, buying or selling cryptocurrencies should be considered a high-risk investment and every reader is advised to do their own research before making any decisions.

Muriuki Lazaro

Journalist

Muriuki Lazaro is a on-chain data analyst with a B.Sc. in Data Science. Muriuki specializes in dissecting complex on-chain data into clear and accurate insights for readers in the crypto ecosystem, with a particular focus on Bitcoin.

AMBCrypto was founded in 2018 with a mission to simplify and bring the latest blockchain and cryptocurrency news to our readers. We have quickly grown into the digital news source for an emerging generation of cryptocurrency enthusiasts, reaching more than a million readers on a monthly basis, across the globe.