Losses from the Coldcard wallet breach have now reached nearly $89 million, tied to almost 4,500 addresses, according to new figures from Galaxy Research. That’s a major step up from earlier estimates, which had counted fewer wallets and lower stolen amounts.

In just the most recent sweep, attackers drained about 208 bitcoin from 1,912 addresses, marking what researchers describe as a third coordinated round. The reason this attack is so difficult to stop comes down to how some Coldcard wallets generated their secret phrases. A firmware change released in March 2021 introduced a predictable path in seed generation on some devices.

That meant attackers could, in some cases, recreate likely wallet keys offline, compare the resulting addresses with funded wallets on the blockchain, and then drain coins without ever touching the device.

Crucially, firmware updates can prevent new weak seeds, but they cannot fix wallets that were already created under the flawed code. Those have to be addressed by moving funds to a fresh wallet created with safe firmware.

The full scale of the compromise may still not be known, as further patterns could emerge across smaller or less active wallets. For now, the story has moved from a targeted incident to a much wider forensic sweep. Each escalation has revealed more systemic exposure, not less.