Wed. Aug 12th, 2026

Coldcard Hack Exposes the Blind Spot in Measuring Self-Custody Losses

ByShane Neagle

August 11, 2026 #Coldcard

The Coldcard hack is exposing one of the hardest problems in crypto forensics: determining how much was actually stolen when thousands of individual self-custody wallets are involved and there is no centralized ledger of victims.

Blockchain analytics firm CryptoQuant currently puts confirmed losses at 1,432 Bitcoin, while Galaxy Research and TRM Labs have traced a substantially higher amount to the attack.

The gap does not necessarily mean one estimate is wrong.

It reflects different standards for deciding when a wallet should be counted as a confirmed victim.

Galaxy Research currently puts its high-confidence minimum at 1,730 BTC, while TRM Labs has estimated that attackers drained roughly 1,816 BTC from more than 5,200 addresses across four separate waves.

CryptoQuant is taking a stricter approach, counting only funds that can be tied back to public victim reports and then verified against known patterns from the attack.

That leaves investigators with several different numbers for the same incident.

And all of them may still move.

Victim Reports Are Driving the Investigation

Galaxy Research’s Alex Thorn said an earlier figure of as much as 1,816 BTC represented a potential loss estimate rather than a confirmed total.

As of Tuesday, Galaxy had raised its high-confidence minimum to 1,730 BTC.

Thorn said more than 450 BTC had been directly confirmed through reports from victims.

Those disclosures have also helped Galaxy identify broader clusters and transaction patterns connected to wallets that had not yet publicly identified themselves as victims.

According to Thorn, victim reports helped uncover more than 730 BTC associated with additional addresses believed to be affected.

Galaxy is still withholding other suspected losses from its formal tally because researchers do not yet have enough independent evidence to classify those wallets with high confidence.

That distinction matters.

Onchain investigators can see Bitcoin moving between addresses, but they cannot always determine why a transaction occurred or whether it was part of a theft.

A wallet that sends funds to an attacker-linked cluster could belong to a victim.

It could also belong to an unrelated user making a legitimate transfer.

Counting every transaction that resembles the attack pattern risks overstating the damage.

Waiting for every victim to report publicly risks understating it.

Self-custody attacks sit directly between those two problems.

TRM Labs Sees Similar Scale

TRM Labs has independently traced losses in roughly the same range as Galaxy.

Its analysis estimates that attackers drained approximately 1,816 BTC from more than 5,200 addresses in four waves.

The number of addresses adds another complication.

One victim may control multiple Bitcoin addresses, meaning address count cannot simply be converted into victim count.

Modern wallets routinely generate new addresses for privacy and operational reasons.

A single user could therefore appear across dozens of addresses.

Investigators must first determine which addresses belong together before attempting to estimate how many individuals were affected.

TRM Labs expects the loss estimate to keep rising before eventually stabilizing.

That pattern is common in decentralized hacks.

Initial figures are based on the most obvious flows. Later reports uncover addresses that were not originally recognized as part of the incident, while additional forensic work can reveal connections between wallets that initially appeared unrelated.

The final estimate may therefore take weeks or longer to settle.

Even then, it is unlikely to become perfectly precise.

CryptoQuant Sets a Higher Bar for Confirmation

CryptoQuant’s confirmed estimate currently stands at 1,432 BTC.

The company begins with public disclosures from users who say they were affected, including wallet addresses or transaction IDs.

Researchers then compare those transactions against known attack patterns.

Only after the evidence matches does CryptoQuant add the Bitcoin to its confirmed tally.

The methodology is deliberately conservative.

CryptoQuant head of research Julio Moreno said identifying victims purely through onchain behaviour could create false positives and artificially inflate the estimate.

Because the stolen Bitcoin came from individuals rather than a centralized entity, there is no single balance sheet or wallet inventory investigators can use to determine the total.

“Knowing the total BTC stolen is difficult, and it will always be an estimation,” Moreno said.

That is the central challenge.

If a centralized exchange loses funds, researchers can usually examine known exchange wallets, compare balances before and after the attack, and build a relatively clear picture of the loss.

With self-custody, every wallet is its own entity.

There may be thousands of users.

Some will report immediately.

Some may wait.

Some may never report publicly at all.

Others may not even realize their wallet was compromised until they attempt to move funds.

The blockchain records the transactions.

It does not label them.

Confirmed Losses and Attributed Losses Are Different Numbers

The difference between confirmed and attributed losses is becoming increasingly important as investigators refine their estimates.

Confirmed losses generally require direct victim evidence or a strong independent link to the attack.

Attributed losses include funds that researchers believe were stolen based on behavioural patterns, clustering and transaction timing, but which have not yet been independently confirmed by the owner.

That is why CryptoQuant can report 1,432 BTC while Galaxy reports a high-confidence minimum of 1,730 BTC and TRM Labs reaches around 1,816 BTC.

The firms are measuring slightly different things.

CryptoQuant is emphasizing certainty.

Galaxy is combining direct victim confirmation with broader pattern-based attribution.

TRM Labs is using independent tracing to reconstruct the attack across thousands of addresses.

Those methodologies may converge over time as additional victims disclose their wallets and researchers obtain more evidence.

For now, the gap provides a useful illustration of how uncertain crypto loss estimates can be in self-custody incidents.

Attackers Have Started Moving Funds

The investigation is also becoming more difficult as stolen assets move through the crypto ecosystem.

Coldcard-linked attackers have already transferred Bitcoin and Ether into cryptocurrency mixers, increasing the complexity of tracing funds once they leave the initial victim wallets.

Mixers combine transactions from multiple users and redistribute funds in ways designed to weaken the direct link between incoming and outgoing addresses.

Blockchain analytics firms can still follow patterns, timing and transaction relationships, but confidence declines as funds pass through more obfuscation layers.

Attackers may also split stolen assets into smaller amounts, route them across multiple wallets or bridge them between blockchains.

Each additional step creates noise.

For investigators, the early hours after an attack are therefore critical.

Victim reports provide the starting points.

Those addresses can then be compared with transactions already identified onchain.

When multiple confirmed victims show similar patterns, researchers can search for other wallets behaving in the same way.

That can uncover victims who have never made a public report.

It also creates the risk of misclassification.

No Single Investigator Has a Complete Picture

Chainalysis has said it has not produced an independent estimate of the total Coldcard losses.

Blockchain investigator ZachXBT has also said he does not intend to monitor or trace the incident.

That leaves several specialized analytics firms building their own models with different evidence thresholds.

Their estimates are likely to remain fluid.

The uncertainty does not mean blockchain tracing has failed.

In some respects, the opposite is true.

Investigators are able to reconstruct large portions of an attack involving thousands of independent addresses without access to a centralized database.

But the Coldcard incident shows the limit of what public blockchains can reveal on their own.

Transactions are transparent.

Ownership is not.

Investigators can see exactly when 10 BTC moved from one address to another.

They cannot automatically tell whether the sender was a victim, whether the address was controlled by the attacker, whether the transaction was legitimate or whether several addresses belong to the same person.

That context has to come from somewhere else.

Often, it comes from the victims.

Self-Custody Changes the Forensic Problem

Crypto users frequently describe self-custody as removing counterparty risk.

In one important sense, that is true.

A user holding Bitcoin in a personal wallet does not depend on an exchange to honor withdrawals or remain solvent.

But self-custody also disperses information.

A centralized exchange knows which accounts were compromised because it controls the account database.

A self-custody wallet provider may have no equivalent record.

That creates a different type of risk.

When something goes wrong, there may be no central authority capable of immediately determining who was affected or how much was lost.

The Coldcard investigation is now demonstrating that problem in real time.

The confirmed loss figure has already climbed as more information has emerged.

It may climb again.

And even after investigators finish tracing the attack, the final number may remain a range rather than a single definitive total.

Coldcard’s Real Problem Is That the Blockchain Knows the Money Moved, Not Who Lost It

This is one of those stories where everyone wants a clean number.

1,432 BTC stolen.

No, 1,730.

Actually 1,816.

Pick one.

But that is the wrong way to read it.

The interesting part is not that investigators disagree.

It is why they disagree.

In a centralized exchange hack, the victim pool is relatively neat. The exchange knows its wallets. It knows customer balances. It knows which accounts were hit. You can argue about attribution, but at least there is a ledger sitting somewhere with names attached to losses.

Self-custody blows that up.

There is no master victim list.

No admin panel.

No support database containing every wallet that got drained.

Just addresses.

Thousands of them.

And that means the forensic job becomes part blockchain analysis, part detective work, part crowdsourcing.

I actually think the gap between CryptoQuant and Galaxy is healthy.

It shows somebody is resisting the urge to slap a dramatic number on the attack too early.

A Bigger Number Is Not Automatically a Better Number

Crypto loves huge hack totals.

They spread better.

“$200 million stolen” gets attention.

“Confirmed minimum is still under review” does not.

But if you are doing forensics, false precision is dangerous.

CryptoQuant is basically saying: show me the victim.

Give me the address.

Give me the transaction.

Then I will count it.

That sounds slow.

It is.

But slow is better than stuffing every suspicious-looking wallet into a spreadsheet because the transaction graph feels right.

On the other hand, Galaxy and TRM are not just guessing.

They are using confirmed victims to build attack fingerprints.

If 20 known victims all show the same drain pattern, same timing and same destination cluster, and another 100 wallets show exactly the same behaviour, it is reasonable to suspect they got hit too.

That is how blockchain intelligence works.

You start with ground truth.

Then expand.

The fight is over how far you are willing to expand before confidence gets mushy.

450 BTC of Direct Reports Is the Hard Core

Galaxy saying it has more than 450 BTC directly confirmed from victims is probably the cleanest number in the whole story.

That is the hard core.

People raised their hands and said: this wallet was mine, this transfer was unauthorized, this is what disappeared.

Everything beyond that becomes progressively more inferential.

Not bad.

Just less certain.

The weird bit is that those confirmed reports can expose much more than the reported losses themselves.

One victim gives you one address.

That address touches another cluster.

The attacker reused a pattern.

Now you find ten more wallets.

Then twenty.

Then hundreds.

Suddenly one report becomes a map.

That is why these estimates rise.

The blockchain is not hiding the money.

It is hiding the context.

More Than 5,200 Addresses Sounds Huge, But Be Careful

TRM says more than 5,200 addresses were involved across four attack waves.

That sounds like 5,200 victims.

It probably is not.

Bitcoin wallets generate addresses constantly.

One person can control dozens.

A hardware-wallet user may never reuse the same receive address twice.

So address count is not user count.

This is a classic crypto data trap.

People see “5,200 addresses” and mentally convert that into “5,200 people got hacked.”

No.

Maybe.

Probably not exactly.

Investigators need clustering to work out which addresses belong together, and even clustering is imperfect.

Privacy practices can split one user across multiple addresses.

Shared services can make multiple users look like one entity.

The graph gets messy fast.

This Is Where Self-Custody Stops Looking Clean

Crypto culture loves the phrase “not your keys, not your coins.”

Fair.

But “your keys” also means “your incident response.”

That part gets less airtime.

If Coinbase gets hacked, Coinbase knows something happened.

If your personal hardware wallet gets drained, nobody necessarily knows unless you tell them.

There is no alarm bell across the system.

No automatic victim registry.

No regulator receiving a neat spreadsheet at 9 a.m.

You are the record.

If you disappear, stay quiet or are too embarrassed to report it, the loss may never make the confirmed count.

That is the dark side of decentralization nobody puts on the merch.

Self-custody removes one kind of counterparty risk.

It also removes centralized observability.

Victim Silence Can Hide a Lot

Some people will never report.

That matters more than it sounds.

Maybe they do not want the public to know how much Bitcoin they held.

Maybe the wallet was tied to something they do not want examined.

Maybe the amount was small.

Maybe they are embarrassed.

Maybe they have no idea which transaction details investigators need.

Maybe they are sitting there thinking support will somehow recover the funds.

Every silent victim creates a hole.

That is why CryptoQuant’s 1,432 BTC should be treated as a floor, not the final bill.

And that is why Galaxy can credibly say 1,730 BTC while still withholding more suspected losses.

Both can be right at the same time.

One is saying “we can prove this.”

The other is saying “we can prove this plus strongly attribute more.”

Different question.

Mixers Make the Next Stage Worse

Once stolen BTC starts moving through mixers, the game changes.

The first hops are usually the cleanest.

Victim wallet.

Drain address.

Consolidation wallet.

Easy enough.

Then attackers split funds, wait, merge them again, route through mixers, bridge assets, swap tokens, move across chains.

Now you are following probabilities.

Not certainty.

People sometimes talk about blockchain transparency like it makes stolen crypto trivial to trace forever.

That is marketing.

The ledger is transparent.

Attribution is hard.

You can see every transaction and still not know who controls the destination.

Mixers make that problem much worse.

And if the attackers are patient, operationally disciplined and willing to sit on funds for months, investigators have a nasty job.

The Four-Wave Pattern Matters

TRM tracing four waves is more interesting to me than the headline BTC total.

Four waves suggests structure.

Not one chaotic drain.

A sequence.

That gives investigators something useful.

Timing.

Repeated behaviour.

Destination overlap.

Fee patterns.

Transaction construction.

Consolidation methods.

Attackers leave habits.

Even competent ones.

If the same process repeats four times, the pattern gets stronger.

That is how Galaxy can move beyond publicly reported wallets without simply guessing.

The more repeated signals you have, the easier it becomes to distinguish attack traffic from normal wallet behaviour.

Still not perfect.

But better.

ZachXBT Sitting This One Out Is Also Interesting

ZachXBT saying he has no plan to monitor the incident matters because people increasingly treat independent investigators like emergency services.

Hack happens.

Everyone tags Zach.

That is not sustainable.

One person should not be expected to trace every large crypto theft.

This ecosystem is supposedly worth trillions. It should not depend on a handful of independent investigators choosing which disaster to spend the next 48 hours on.

Galaxy, TRM, CryptoQuant and others doing parallel analysis is healthier.

Different methods.

Different thresholds.

Then compare.

That is how you avoid one bad assumption becoming industry consensus.

The Number Will Probably Rise

I would be surprised if 1,432 BTC is the final number.

That is not because CryptoQuant’s work looks weak.

The opposite.

Their threshold is strict enough that more victim reports should naturally push the tally higher.

Galaxy is already at 1,730 BTC with a high-confidence minimum.

TRM is around 1,816 BTC.

The spread is not huge considering the mess they are working with.

That actually gives me more confidence that the real loss probably sits somewhere near the upper end of the current range, assuming no major attribution error appears.

But I would not print 1,816 BTC as gospel yet.

Too early.

Self-Custody Security Has an Accounting Problem Too

Most people frame wallet security as a technical issue.

Seed phrases.

Firmware.

Phishing.

Supply-chain attacks.

Malicious software.

All true.

But there is also an accounting problem after the hack.

Who got hit?

How much?

Which transactions count?

Which wallets belong to the same person?

What was actually stolen versus voluntarily moved?

This matters for insurers.

It matters for law enforcement.

It matters for exchanges receiving tainted funds.

It matters for lawsuits.

It matters for understanding whether the attack was a limited incident or a systemic wallet compromise.

If your starting number is wrong by hundreds of BTC, every later decision gets distorted.

The Blockchain Is Transparent Until You Ask a Human Question

This is the contradiction I keep coming back to.

Bitcoin gives investigators perfect transaction history.

Every satoshi moves in public.

Then ask the most basic question imaginable:

How many people lost money?

Suddenly nobody knows.

That is not a failure of Bitcoin.

It is the boundary of what the ledger was designed to tell you.

The chain records ownership changes between addresses.

It does not record intent.

It does not say “the owner approved this.”

It does not say “this wallet belongs to the same person as those seven.”

It definitely does not stamp a transaction with “theft.”

Humans add that layer.

And humans are messy.

What I’d Trust Right Now

I would not anchor to one exact BTC number yet.

The useful way to read the evidence is:

CryptoQuant gives you the conservative floor.

Galaxy gives you a broader high-confidence estimate.

TRM gives you a reconstructed attack total based on independent tracing.

That is enough to say the loss is already enormous without pretending the final number is settled.

The real test comes when reporting slows down.

If new victim disclosures stop and the estimates converge, confidence rises.

If another wave of addresses gets corroborated, the number jumps again.

That is the game.

For now, anyone claiming the Coldcard loss is exactly 1,432 BTC or exactly 1,816 BTC is pretending the evidence is cleaner than it is.

It isn’t.

And that uncertainty is the story.

The hack did not just steal Bitcoin.

It exposed how hard it is to count damage when every victim is their own bank.

ByShane Neagle

Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms. He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments. Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

Leave a Reply

Your email address will not be published. Required fields are marked *