Coldcard exploit now hits 4,585 wallets – Attacker still holds $88.6M stolen BTC

The Coldcard exploit continues increasing as investigators uncover extra affected wallets and stolen Bitcoin.
A current discovery by Galaxy Analysis now hyperlinks the incident to 4,585 addresses drained throughout three waves, totaling 1,367.05 BTC value about $88.6 million.
The newest wave alone drained 207.73 BTC from 1,912 addresses, extending earlier estimates of two,673 wallets and 1,158.81 BTC. Extra importantly, investigators discovered the stolen Bitcoin [BTC] stays 100% unspent, indicating the attacker prefers consolidation over quick liquidation.


That habits suggests operational planning quite than opportunistic promoting, leaving the funds prepared for future motion. Because the investigation progresses, extra linked addresses might emerge, additional increasing the suspected scale and timeline of the exploit.
Publish-exploit Bitcoin actions
That broader investigation now gives clearer perception into the attacker’s technique after the preliminary theft. Onchain Lens exhibits the exploit cluster obtained 1,159.42 BTC, value about $72.71 million, from 870 compromised addresses earlier than consolidating the funds into eight verified wallets.


Nonetheless, the attacker has moved solely 0.06 BTC to a recent handle, leaving roughly 1,159.35 BTC untouched.
Quite than signaling quick liquidation, this sample suggests the attacker is prioritizing management, group, and lowering publicity earlier than making an attempt bigger transfers.
It additionally retains most stolen Bitcoin seen on-chain, permitting investigators to observe future actions.
However, as soon as funds start leaving these clusters extra often, the probability of laundering or broader distribution would improve considerably.
Can blockchain monitoring sustain?
Though the attacker has not begun broader distribution, the investigation now enters a extra decisive part. Future on-chain actions will reveal whether or not the operation shifts from fund administration to fund extraction.
Transfers to regulated exchanges might expose identities by means of KYC procedures, creating alternatives for intervention.
In distinction, actions by means of mixers or cross-chain bridges would fragment the transaction path and complicate blockchain evaluation.
Transaction frequency, handle clustering, and routing patterns will due to this fact change into extra vital than steadiness measurement alone. Continued inactivity would protect clear investigative leads and strengthen monitoring efforts.
Nonetheless, coordinated outbound transfers would mark the transition from a contained incident into a much more complicated tracing problem.
Closing Abstract
- The suspected Coldcard exploit continues increasing as investigators hyperlink extra wallets to the stolen BTC.
- Future Bitcoin actions will decide how successfully investigators can proceed monitoring the stolen funds.




