The number of known victims linked to the COLDCARD seed-generation incident has climbed to 256, while the latest tracking attributed to Galaxy Research puts the broader Bitcoin tally at 1,830 BTC.
A September 27 update based on monitoring by Galaxy Head of Firmwide Research Alex Thorn said 256 victims had now reported their cases to GLXY Research. The median reported loss was 1.1 BTC, with the investigation identifying three principal attack rounds and more than 30 smaller associated incidents or indicators.
The attacker-tracing effort remains active.
The figures substantially sharpen the picture of an incident that was initially measured mainly through suspicious Bitcoin addresses and large on-chain sweeps. Galaxy said in August that more than 200 victims had contacted its researchers as it tracked funds associated with the compromised wallets. The latest 256-victim count provides a better, although still incomplete, indication of how the losses were distributed among individual holders.
The numbers remain an independent and evolving research tally. Coinkite, the Canadian company behind COLDCARD, has not published a definitive aggregate figure for Bitcoin stolen from customers.
There is also an important qualification around the 1,830 BTC figure. Earlier September tracking tied 52.37 BTC from COLDCARD-related clusters to white-hat operators who moved vulnerable funds into a recovery trust rather than stealing them for their own benefit. That means the 1,830 BTC headline should not automatically be interpreted as 1,830 BTC permanently lost to malicious attackers. It is better understood as the current scale attached to the incident while researchers continue separating malicious theft, rescued funds and additional related activity.
The Median Victim Lost 1.1 BTC, but the Distribution Could Be Much More Uneven
The median loss of 1.1 BTC is one of the most revealing additions to the investigation.
Previous estimates established that thousands of Bitcoin addresses had been affected, but an address is not the same thing as a person. One wallet seed can generate many addresses, making address counts a poor proxy for the actual number of investors caught in an incident.
The 256 people who contacted researchers provide a more useful victim-level sample. A median of 1.1 BTC means half of those reported victim losses were above that level and half below it.
It does not mean the average victim lost 1.1 BTC, and dividing the full 1,830 BTC tally by 256 would be misleading. The broader on-chain total includes addresses that may not belong to people who have contacted Galaxy, while the incident mapping has also included funds subsequently identified as white-hat recoveries.
Still, the median suggests this was not primarily an attack on wallets containing dust or experimental balances. A meaningful number of affected users appear to have been long-term holders storing economically significant amounts of Bitcoin in hardware wallets specifically because they wanted to reduce custody risk.
That gives the incident a different profile from the recent D’CENT XRP drain, where thousands of software-linked wallet credentials remained usable after the initial thefts. In COLDCARD’s case, the danger was created when the seed itself was generated.
A Firmware Error Made Some Wallet Seeds Searchable Offline
Coinkite says the COLDCARD devices were not remotely hacked or taken over. Instead, a firmware integration error caused affected devices to generate seeds with substantially less randomness than intended.
Normally, a hardware wallet relies on cryptographically secure entropy when generating the secret from which its wallet keys are derived. In affected COLDCARD releases, the seed-generation path resolved to a software pseudo-random-number generator rather than the intended hardware random-number generator.
Galaxy estimated that affected Mk2 and Mk3 seeds could have contained roughly 40 bits of effective entropy, while newer Mk4, Q and Mk5 devices had around 72 bits rather than the expected 128 bits.
That reduction changed the economics of attacking the wallet. Instead of obtaining the physical device, stealing a backup phrase or infecting the owner’s computer, attackers could generate candidate seeds offline and compare the resulting Bitcoin addresses against the public blockchain.
Coinkite’s security advisory identifies Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 as affected. Seeds created on Mk4 and Mk5 before standard firmware 5.6.0 or Edge 6.6.0X are also affected, as are Q seeds generated before standard 1.5.0Q or Edge 6.6.0QX.
The company says independently adding at least 50 fair, private dice rolls during seed generation provided enough separate entropy to avoid the vulnerability from this issue alone. A strong, unique BIP-39 passphrase also creates an additional barrier, although Coinkite continues to recommend migration.
Most importantly, installing corrected firmware does not fix an existing vulnerable seed. Users have to generate an entirely new seed with corrected software and migrate the assets.
That distinction echoes a broader custody problem highlighted when a 4,500 BTC cold wallet became inaccessible for an entirely different reason: holding Bitcoin offline only works if the key-management process around it also works.
The Remaining Unswept Wallets May Matter More Than the 1,830 BTC Already Identified
The most important number now may not be the amount already linked to the incident.
It may be the Bitcoin still sitting behind vulnerable seeds.
Once a seed has been generated with insufficient entropy, time does not repair the problem. A wallet can sit untouched for years and still remain exposed if an attacker eventually reconstructs its key material.
That creates an unusual security race. The first attack waves alerted COLDCARD owners to migrate, but they also demonstrated publicly that the reduced key space could be exploited. Every wallet successfully moved to a fresh seed disappears from the attack surface. Every funded wallet left behind remains a potential target.
This is why the eventual distribution of the 256 reported victims matters. If researchers can determine when their seeds were created, which COLDCARD models and firmware versions they used and how losses cluster across those periods, the data could reveal where attackers concentrated their computing resources and where unswept exposure may remain.
The industry has recently seen several very different ways in which supposedly secure authorization can fail. Bitget said its private keys survived while a backend wallet system was compromised. Another recently disclosed issue showed how signer security flaws can produce economically dangerous transactions even when key extraction is not the problem.
COLDCARD represents an even earlier failure point: the secret itself was weaker from the moment it was created.
Self-Custody Did Not Fail — but One of Its Simplest Assumptions Did
The unsettling part of this incident is that many victims may have behaved exactly as hardware-wallet users are normally told to behave.
They kept Bitcoin off exchanges. They held their own keys. Some may have kept the physical devices offline for years. None of that protects a wallet if an attacker can reconstruct the key without ever touching the device.
That does not make self-custody inherently unsafe. It does make the usual slogan around controlling your own keys incomplete.
You also have to trust how those keys were created.
For investors with substantial Bitcoin balances, that shifts attention toward redundancy: independently generated entropy, strong passphrases, multisignature structures and avoiding a setup where one implementation can silently become the single point of failure for an entire portfolio.
The latest 256-victim count makes that lesson harder to dismiss as a theoretical firmware problem. It now describes hundreds of people who have actively contacted researchers, a median reported loss above one Bitcoin and an incident tally measured in thousands of BTC.
The next stage of the investigation should be less about making that headline number larger and more about explaining what sits underneath it: how losses are distributed, which seed-generation periods produced the largest exposure, how much of the mapped Bitcoin was maliciously stolen versus rescued by white hats, and whether funded vulnerable wallets remain waiting to be swept.
Until those questions are answered, 1,830 BTC is not a final accounting. It is a moving boundary around an incident whose remaining exposure may still be hidden in wallets that have not moved at all.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

