Tue. Sep 8th, 2026

Researcher Claims Coldcard RNG Losses May Have Reached $406 Million

ByShane Neagle

September 8, 2026 #Coldcard
Crypto Hack

Independent Analysis Identifies 35,189 Drained Bitcoin Addresses

An independent security researcher has challenged prevailing estimates of the Coldcard hardware wallet exploit, claiming an onchain reconstruction indicates roughly 5,080 BTC was stolen from wallets generated with weak randomness — more than twice the losses identified by several established blockchain investigators.

The estimate would put the value of the stolen bitcoin at approximately $406 million using a reference price of about $79,900.

The figure remains independently unverified and is substantially higher than estimates published by Galaxy Research, TRM Labs and other firms investigating the incident.

Mikhail Martynyuk, an independent crypto security researcher who publishes under the name MadMike, said he reconstructed approximately 2,052 vulnerable wallet seeds and identified 35,189 Bitcoin addresses associated with them.

All of the identified addresses have been drained, according to his analysis.

Martynyuk published a repository containing the affected address list, consolidation-hub data and a detailed description of his methodology, allowing outside investigators to test at least part of the reconstruction.

His analysis distinguishes between approximately 10,950 BTC that passed through addresses generated from the allegedly compromised seeds and a smaller net-loss figure of 5,079.90 BTC.

The difference is significant because simply adding all bitcoin received by compromised addresses could count the same funds multiple times as change moved between addresses controlled by the same wallet.

Martynyuk said his transaction-graph analysis removed this internal cycling to arrive at the roughly 5,080 BTC theft estimate.

That number remains far above other published assessments.

Galaxy Research said in late August that it had attributed 1,789.28 BTC stolen from 8,865 addresses to the Coldcard incident. Earlier analysis from TRM Labs tracked approximately 1,816 BTC across multiple attack waves.

Galaxy’s methodology has relied partly on direct victim reports and high-confidence identification of attacker footprints, creating a more conservative standard for attributing losses to the Coldcard vulnerability.

The new research takes a different approach.

Rather than beginning primarily with known theft transactions, Martynyuk said he attempted to recreate the population of seeds generated by the vulnerable random-number generation process and then derived addresses associated with those wallets more deeply than previous public analyses.

He argues that this uncovered large numbers of change and deeper-derivation addresses that were missed by trackers focused on the highly visible mass sweeps beginning July 30.

His reconstruction claims the theft activity stretches back to July 2021 and consists of 202 separate drain waves, potentially indicating that vulnerable Coldcard wallets were being exploited years before the large-scale attack became public.

The report further claims an automated sweeper remained active as recently as Aug. 19.

That finding would also differ from Galaxy’s earlier assessment that it had not identified high-confidence new attacker activity after Aug. 6, although Galaxy continued to discover additional historical losses as victims came forward.

Martynyuk estimates that approximately 2,918 BTC from the reconstructed theft remains parked in attacker-linked addresses, while about 991 BTC reached cryptocurrency exchanges or other identified services.

Those classifications rely on transaction-graph tracing and attribution assumptions and have not been independently confirmed by the exchanges or major blockchain intelligence firms.

The underlying Coldcard vulnerability itself is no longer disputed.

Coinkite disclosed in July that a firmware integration error caused some Coldcard devices to generate wallet seeds using a weak software pseudo-random number generator instead of the intended hardware source of cryptographic randomness.

The problem entered the firmware lineage in 2021.

Because the resulting seeds contained substantially less entropy than users expected, attackers could attempt to reconstruct private keys offline without possessing or remotely compromising the physical Coldcard device.

Once a vulnerable seed was discovered, every Bitcoin address derived from it could potentially be controlled by the attacker.

Coinkite has since patched the seed-generation process and repeatedly warned that installing new firmware does not repair a seed generated under vulnerable firmware. Affected users must create a new seed and move their bitcoin.

The company has acknowledged that customers suffered real losses but has not published an official aggregate theft figure, while law enforcement continues investigating the attacks.

That leaves the true scale of the incident unresolved.

The newly published dataset could now provide one way to test whether the Coldcard exploit was primarily a concentrated series of attacks around the July disclosure or a much larger pattern of theft stretching back several years.

The $406 Million Claim Needs to Survive Outside Verification

The difference between 1,800 BTC and 5,080 BTC is too large to treat as a rounding error.

If the new reconstruction is substantially correct, the Coldcard incident has been misunderstood not only in size but also in duration.

The public narrative has largely centered on a spectacular series of sweeps beginning July 30. The independent research instead suggests the visible attack was only the moment when a much older exploitation pattern became impossible to ignore.

That would be a very different security failure.

But a larger dataset does not automatically make a larger estimate correct.

Blockchain attribution becomes increasingly difficult as researchers expand outward from transactions known to belong to victims.

Galaxy’s approach is deliberately conservative. Direct victim reports and matching attacker fingerprints provide relatively strong evidence that a particular address belongs in the Coldcard dataset.

Brute-forcing a vulnerable seed and discovering addresses derived from it potentially provides another powerful form of evidence, but the methodology needs to be independently reproduced.

The key question is whether the researcher really reconstructed the vulnerable seed space accurately enough to distinguish Coldcard-generated wallets from unrelated wallets that happen to match some element of the search.

Then comes the accounting problem.

Bitcoin wallets generate large numbers of addresses. Funds move through change addresses, consolidations and repeated transactions. Adding every movement together can produce a headline number dramatically larger than the actual economic loss.

Martynyuk explicitly attempts to solve that by separating internal change cycling from external deposits. That is encouraging, but the resulting 5,079.90 BTC figure still needs another forensic team to reproduce it from the underlying transaction graph.

The same caution applies to the claim that 991 BTC reached exchanges.

Blockchain intelligence firms spend significant resources identifying exchange clusters, mixers, bridges and other services, and their labels are constantly revised. An independent researcher can produce a plausible attribution without that attribution necessarily being strong enough for an exchange, investigator or court to rely on.

This is why the repository matters.

Most dramatic crypto-hack claims arrive as screenshots, unexplained wallet lists or social media threads that outsiders cannot realistically audit.

This one includes a public list of 35,189 addresses and describes how the researcher arrived at the larger tally.

That does not make the result verified. It makes it falsifiable.

Galaxy, TRM Labs, Chainalysis or another experienced blockchain-forensics team should be able to take that address set and determine how much overlap exists with wallets they already attribute to the Coldcard vulnerability.

Even partial confirmation would be consequential.

If thousands of previously unidentified addresses can be tied with high confidence to weak Coldcard seeds, the known loss total could rise substantially even if the full $406 million estimate does not survive scrutiny.

The claim of exploitation dating back to 2021 may be even more important than the headline dollar figure.

A vulnerability that was discovered and rapidly exploited is one type of failure.

A vulnerability quietly harvested for years before a mass drain is another.

For now, the responsible headline is not that $406 million was definitely stolen.

It is that a researcher has produced a testable dataset claiming the Coldcard disaster was far larger than currently accepted estimates — and the next step belongs to independent forensic firms that can prove him right or wrong.

ByShane Neagle

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms. He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments. Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *