The bitcoin theft that began with a five-year-old firmware bug is no longer just a whale problem. Galaxy Research flagged a third wave of wallet sweeps early Sunday, August 2, 2026 — roughly 208 BTC drained from 1,912 addresses between Friday midday and Saturday morning UTC. That works out to just over a tenth of a bitcoin per victim, a sharp drop from the near one-coin average of the opening wave. Observed losses across all three waves now total 1,367 BTC, close to $89 million at recent prices, taken from 4,585 addresses, according to CoinDesk's August 2 report on Galaxy's analysis.

In plain terms: the attacker (or attackers) working through weak Coldcard-generated keys has moved down-market. After emptying the large, dormant wallets in the first 41-minute burst on July 30, the sweeps are now hitting everyday holders with a few thousand dollars each — the long tail of a vulnerable key space that is, in Galaxy's reading, already largely picked over at the profitable end.

From one big heist to thousands of small ones

The escalation has been fast. The opening wave on July 30 took 1,083 BTC from 1,196 addresses in about 41 minutes, averaging close to a full coin per victim. A second wave followed, and by Saturday Galaxy's count of linked losses had reached roughly $89 million. The third wave's average haul of about 0.11 BTC per address tells its own story: the attacker is scraping smaller balances because the big ones are gone.

WaveWindowBTC takenAddressesAvg per victim
Wave 1July 30, ~41 minutes1,083 BTC1,196~0.9 BTC
Wave 2July 30–31~76 BTC (balance of linked losses)~1,477small balances
Wave 3Fri midday–Sat morning UTC (Jul 31–Aug 1)~208 BTC1,912~0.11 BTC
Total observedJuly 30 – August 11,367 BTC (~$89M)4,585

Source: Galaxy Research figures as reported by CoinDesk, August 1–2, 2026. Wave 2 row is inferred from the difference between reported totals.

The tradecraft changed too. Where the first two waves funneled stolen coins into a handful of shared collector addresses that made them easy to map, wave three sends each victim's coins to its own destination and parks them in pay-to-witness-script-hash (P2WSH) outputs — a format that can carry multisignature or timelock conditions — instead of the plain single-key outputs used before. It batched an average of six victims per sweep transaction and scanned only the default derivation path of each seed. Galaxy says it is confident each wave is internally the work of a single operator, but it will not link the three waves to one another: the chain simply cannot distinguish one attacker rebuilding from a second one grinding the same vulnerable key space independently.

Why this keeps happening: the March 2021 bug

The root cause has not changed since the story broke on July 30. Coldcard firmware version 4.0.0, released in March 2021, routed seed generation to a predictable software pseudorandom number generator instead of the STM32 chip's hardware RNG. That left a bounded set of possible keys that anyone with the disclosure and enough compute can reproduce offline — no physical access to any device required. Maker Coinkite has acknowledged the bug, apologized, and shipped emergency firmware, but has stressed that updating firmware does not fix an already-created vulnerable seed. Users who generated seeds on affected versions need to create entirely new seeds on patched devices and migrate their funds.

One notable non-event: the 562 BTC that the first-wave attacker consolidated into a single address (bc1qq85v2c926eg6pgxhwp6q7lf6cnsz80qs3fcu9r) has still not moved as of Sunday. Every exchange and analytics firm is watching that address; any movement toward a mixer or exchange would be the next major development in this story.

CZ: 'Nothing is 100%' — split your funds

The incident has drawn responses from the industry's biggest names. On Saturday, Binance founder Changpeng Zhao — CZ — urged holders to stop treating a single hardware wallet as a vault, in a post on X quoted by CoinDesk:

"Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs. How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!" — Changpeng Zhao (CZ), August 1, 2026

Strike CEO Jack Mallers has called the drain one of the most serious bitcoin hacks ever, and CoinDesk reported Friday that the episode is pushing some investors to reconsider ETFs over self-custody — an ironic turn for an attack that struck the exact product class marketed as the safest way to hold your own coins.

Market reaction: pressure, not panic

Bitcoin has absorbed the news without breaking down. BTC traded near $62,900 on Sunday, August 2, per Investing.com data — down about 1.3% over 24 hours and just below Friday's monthly close around $62,929, which locked in a roughly 7.5% gain for July, the best month in a year per CoinDesk. Analysts quoted by CoinDesk expect a 'choppy' August, arguing most forced selling was already spent in June. The exploit is a persistent headline drag rather than a systemic risk: the vulnerable key space is finite, disclosed, and closing — but as wave three shows, it is closing victim by victim.

What affected users should do now

If you hold coins on a Coldcard whose seed was generated on firmware 4.0.0 or later affected builds — especially seeds created between March 2021 and the patched releases — treat the seed as compromised even if your balance is untouched. Move funds to a wallet with a freshly generated seed on patched firmware or different hardware entirely, and do it deliberately: wave three proves small balances are now being targeted, so 'too small to matter' is no longer protection. Our companion guide walks through a safe migration step by step, and yesterday's explainer covers how seed entropy failed in the first place.

Disclaimer: This article is for informational and educational purposes only and does not constitute investment, financial, legal, or tax advice. Cryptocurrency prices are highly volatile and you can lose your entire investment. Always do your own research and consult a qualified financial advisor before making any investment decision.