Analysts from Galaxy Research have just detected alarming asset traffic within the network. In a recent finding, it was revealed that an attacker transferred approximately 1,083 BTC from more than 1,000 different addresses, with the entire draining process fully executed in just 41 minutes starting on July 30, 2026.
Unfortunately, the flash attack at the end of July was just the beginning. The wave of forced fund transfers has continued to claim new victims and went on without interruption into mid-August 2026. According to several public reports, the total losses from this breach are claimed to have reached hundreds of millions of dollars, with one calculation citing a figure of $112 million. The wide scale of this incident triggered price volatility for major assets such as BTC, ETH, and XRP in the open market.
Five-Year-Old Flaw in the Device
The large number of addresses breached in close proximity initially sparked speculation. However, tracking proved that this is not a security vulnerability in the Bitcoin blockchain. Instead, the attacker’s entry point originated from the hardware wallet used by the users, specifically in the random number generator mechanism inside certain Coldcard firmware when generating the wallet’s seed phrase.
The seeds of this disaster were planted five years ago. The root of the problem stems from a firmware update released by the wallet manufacturer, Coinkite, in 2021. That update introduced a flaw into the recovery phrase generation process when users set up their wallets. This flaw compromised the system, making the seed phrases generated by several firmware versions predictable. Through this readable pattern, the attacker was ultimately able to derive the private keys without needing to touch the victims’ physical devices.
Why a System Update Alone Is Not Enough
A prominent fact of this incident is its timeline. Several security researchers had actually tracked and reported this issue to Coinkite long beforehand. Even though the vulnerability had been reported, the large-scale attack only erupted now. Currently, certainty regarding how wide the range of affected devices is and which specific firmware versions are impacted still awaits official confirmation from Coinkite.
The most crucial thing for wallet owners to understand is that updating the firmware will not fix the situation. While the new firmware version can generate a new wallet securely, it cannot repair the old seed phrase that was already created using the compromised system.
For users, the only way out is to move their assets. All funds must be transferred to a new, secure address, in line with the mitigation recommendations from the manufacturer. For users who believe their device was compromised or whose funds were swept up in that wave of transfers, official reporting channels are open. Users can directly contact the FBI’s Internet Crime Complaint Center or IC3, as well as visit their local field office for further steps.
Sourced from crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




