# Coldcard Attacker Begins Mixing Stolen Bitcoin as Volunteer Auditors File 85 Critical Bugs Across Bitcoin Code

Galaxy Research says the largest identified attacker address still holds 1,159 bitcoin untouched. The Bitcoin Red Team has logged 4,962 findings across 390 open-source repositories since the theft.

- Published: 2026-08-06T05:48:34.076Z
- Canonical: https://polylog.news/crypto/2026-08-06/coldcard-attacker-begins-mixing-stolen-bitcoin-as-volunteer
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [crypto.news](https://crypto.news/coldcard-attacker-holds-1159-btc-as-mixing-starts/), [Bitcoin Magazine](https://bitcoinmagazine.com/business/bitcoin-red-team-finds-85-critical-flaws-across-390-open-source-repos-after-coldcard-exploit), [CoinDesk](https://www.coindesk.com/tech/2026/08/05/coldcard-exploit-could-boost-demand-for-regulated-bitcoin-exposure-analysts-say), [Bitcoin Magazine (opinion)](https://bitcoinmagazine.com/culture/self-custody-is-dead-long-live-self-custody), [Bitcointalk](https://bitcointalk.org/index.php?topic=5589927.0)

There is new movement in the theft that drained bitcoin from users of COLDCARD hardware wallets. On-chain investigators [told crypto.news](https://crypto.news/coldcard-attacker-holds-1159-btc-as-mixing-starts/) that the largest known attacker address, which holds 1,159 bitcoin (BTC), remains untouched. A separate attacker has started sending smaller amounts through a mixing service. Galaxy Research is tracking the balances.

The root cause is not a smart-contract bug but a defect in how the device created keys. A firmware build from March 2021 routed wallet seed creation through a software random number generator (RNG) instead of the hardware one. That narrowed the range of possible seeds and made affected wallets reconstructible by anyone who found the flaw. Thefts began on 30 July from long-dormant addresses. Loss estimates diverge: [BleepingComputer put the total near 1,367 BTC, about $88 million](https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/), while [Bitcoin Magazine describes over $100 million drained](https://bitcoinmagazine.com/business/bitcoin-red-team-finds-85-critical-flaws-across-390-open-source-repos-after-coldcard-exploit) and [TechCrunch reported more than $130 million](https://techcrunch.com/2026/08/04/hackers-steal-over-130-million-by-exploiting-bug-in-offline-hardware-wallets/). No funds have been recovered or frozen, and no attacker has been identified. Manufacturer Coinkite shipped patched firmware and told users with seeds generated on affected versions to move their funds, a warning [amplified on Bitcointalk](https://bitcointalk.org/index.php?topic=5589927.0).

The response has become an audit campaign. The Bitcoin Red Team, led by the developer known as Calle and by Rob Hamilton, says it has filed 4,962 findings across 390 open-source repositories, 85 of them rated critical. The group uses artificial-intelligence-assisted code review to search for the same class of entropy and implementation errors.

Analysts are treating the episode as a question about custody. Cantor expects regulated custody providers to benefit, and FRNT expects some holders to shift toward bitcoin exchange-traded funds (ETFs), [according to CoinDesk](https://www.coindesk.com/tech/2026/08/05/coldcard-exploit-could-boost-demand-for-regulated-bitcoin-exposure-analysts-say). Bitcoin Magazine's own commentary [argues the opposite conclusion](https://bitcoinmagazine.com/culture/self-custody-is-dead-long-live-self-custody), that a vendor defect is a reason to improve key practice rather than to hand keys to intermediaries.

## What this means

The failure sits in key generation, which no on-chain security review would catch, so the exposed group is holders who did exactly what self-custody guidance told them to do and used pre-2021 seeds. The immediate beneficiaries are regulated custodians and ETF issuers, who collect assets each time private key management looks unreliable. The losers are hardware vendors whose certification claims now require independent entropy verification to be credible. A second consequence runs through supply: decade-old balances that move because of theft are no longer a reliable signal of long-term holder intent.

## What to watch

- Whether the 1,159 bitcoin in the largest attacker address moves, and whether it goes to a mixing service or to an exchange deposit address, which would tell investigators how confident the attacker is about cashing out.
- Whether other hardware wallet makers publish independent audits of their entropy sources, which would show the industry treating this as a category-wide defect rather than one vendor's error.
- Flows into bitcoin ETFs and regulated custody in the coming weeks, the clearest measure of whether the theft actually pushed holders away from personal key management.
