The Coldcard security incident has grown into a much bigger story than many Bitcoin users expected. What began as a suspected wallet flaw tied to seed generation has now expanded into a third attack wave, pushing estimated losses to 1,367.05 BTC, or about $88.6 million.
What Happened To Coldcard Bitcoin

According to Galaxy Research, the latest wave drained another 207.7294 BTC from 1,912 addresses, adding to two earlier waves that had already moved large amounts of Bitcoin. In total, the incident now appears to cover 4,585 addresses, making it one of the more widely distributed self-custody losses tracked this year.
The first wave was especially fast. Galaxy said 1,082.65 BTC was swept from 1,196 addresses in about 41 minutes on July 30, with the second wave following shortly after and the third wave raising the total even further.
Why the Issue Is Serious

The concern is not just that funds were stolen. The more worrying part is the possibility that some Coldcard-generated seeds were weak enough for attackers to reproduce private keys offline, meaning the security failure may have started at wallet creation rather than during storage.
That matters because many users believe hardware wallets are automatically safe. In reality, if the seed generation process is flawed, the wallet can be vulnerable even when it never connects to the internet.
Which Users May Be Affected

Reporting from Galaxy and related coverage suggests the issue may involve wallets created on affected Coldcard versions beginning with the 4.0.0 era, with the vulnerable period stretching from March 2021 until the patched 4.21 release. Coinkite’s advisory said wallets with mnemonic phrases generated before 4.21 may be at risk in theory.
That does not mean every Coldcard owner lost funds. But it does mean any user who created a seed on a potentially affected device should treat the situation as urgent and verify whether their wallet setup is safe.
What Users Should Do

If there is any chance a wallet was created with a vulnerable seed, the safest move is to migrate funds to a new wallet with a fresh, verified seed. Users should also avoid reusing old seed phrases or assuming a firmware update alone is enough to fix an already exposed wallet.
For anyone managing larger Bitcoin holdings, this is a reminder to check wallet provenance, seed generation method, and backup integrity. Self-custody only works when every step is secure, from seed creation to long-term storage.
Understanding how to protect your seed phrase is one of the most important steps in securing your Bitcoin.
Bigger Takeaway for Bitcoin Users

The Coldcard case is a strong example of how one technical weakness can turn into a large-scale loss event. Once attackers can identify vulnerable addresses, the damage can spread quickly and quietly across thousands of wallets.
It also shows how security incidents in crypto often evolve in waves. The loss estimate rose from about $70 million to $75 million, and then to $88.6 million as more on-chain activity was connected to the same flaw.
Conclusion
The third wave confirms that the Coldcard incident is still unfolding and may continue to affect how users think about hardware wallet safety. For Bitcoin holders, the main lesson is simple: a hardware wallet is only as strong as the seed behind it

