Investigators tracking the Coldcard hardware wallet exploit have confirmed losses exceeding 1,596 Bitcoin, now valued over $100 million. What started as an apparent single breach has snowballed into a sprawling forensic puzzle spanning multiple attack waves and thousands of compromised addresses.

The initial discovery flagged roughly 4,585 addresses hit across three waves, with 1,367 Bitcoin stolen worth $88.6 million. As blockchain analysts dug deeper, they uncovered an additional 1,912 affected addresses, adding another 207.73 BTC to the tally. The key detail: every single stolen coin remained untouched. No liquidation, no movement to exchanges. The attacker sat on the funds.

That passivity told investigators something important. Rather than rush to cash out, the perpetrator prioritized consolidating stolen assets. This behavior pattern became the backbone of tracing attacker-controlled wallets. Galaxy Research identified 14 smaller related incidents alongside the main theft waves, pushing suspected total losses toward 2,000 BTC or roughly $130 million. A potential fourth wave could add another 459 BTC if victims confirm their inclusion in the attack.

The blockchain breadcrumbs

Blockchain forensics revealed something striking: 90 percent of stolen Bitcoin has never moved. Every coin from Waves 1, 2, and 3 sits dormant in its receiving address. That inactivity, counterintuitively, strengthens the investigation. Dormant funds leave a clearer trail for investigators to map attacker-controlled wallets and link additional addresses to the exploit. Meanwhile, newly discovered smaller theft events suggest opportunistic actors jumped in after the initial compromise, exploiting similar conditions.

Investigators are now sharing verified addresses with law enforcement, exchanges, and compliance firms. The goal is straightforward: track any future fund movements before the attacker finds a way to cash out. The longer those billions sit untouched, the more time investigators have to build their case.

Beyond the forensic mechanics, the exploit hammers at one of Bitcoin's core assumptions about self-custody. This incident didn't expose a flaw in self-custody itself. Rather, it exposed the need for hardware wallet manufacturers to strengthen their security infrastructure against increasingly sophisticated attacks targeting the custody layer.

This article is informational and does not constitute financial advice. Consult a qualified financial professional before making investment decisions.