Bitcoin thefts linked to a flaw in Coldcard hardware wallets have now reached $88.6 million in cumulative losses. Galaxy Research says 1,367.05 Bitcoin has been drained across 4,585 addresses in multiple attack waves, all tied to a seed-generation weakness dating back to March 2021. The bug weakened the randomness used to create recovery seeds. That let attackers guess likely seeds offline, generate the bitcoin addresses tied to them, and then check which of those addresses held funds on the public blockchain.

Galaxy says the thefts came in several waves, including earlier sweeps on July 30 and July 31, with a fourth suspected wave on August 3.

For affected users, the key point is this: installing the latest firmware does not make an older wallet safe if its seed was created under the vulnerable software. Coinkite has issued patched firmware, but it also says those older seeds should be treated as exposed and replaced. In practice, that means creating a new seed on updated firmware and moving funds. Simply upgrading is not enough.