Investigators Trace Bitcoin After Coldcard Wallet Hack

Blockchain firms report confirmed Coldcard hack losses from 1,432 BTC to about 1,816 BTC as investigators trace victim addresses and on-chain flows.

Blockchain investigators are tracing Bitcoin stolen in a hack of Coldcard hardware wallets. Analytics firms report confirmed losses ranging from 1,432 BTC to roughly 1,816 BTC as they work to identify victim addresses and link transactions on-chain.

CryptoQuant places its confirmed total at 1,432 BTC. Julio Moreno, head of research at CryptoQuant, described that figure as a conservative floor based only on publicly disclosed wallet addresses and transaction IDs. Moreno warned the tally could rise if more victims publicly identify stolen addresses and stressed the firm limits confirmations to victim disclosures: “Because the stolen Bitcoin belonged to individuals and not to a centralized entity, like an exchange, we can only confirm what each victim publicly discloses.”

Galaxy Research and TRM Labs report higher totals by combining confirmed victim reports with additional on-chain patterns attributed to the same exploit. Galaxy’s earlier potential estimate reached about 1,816 BTC; the firm later set a high-confidence minimum at 1,730 BTC. Analyst Alex Thorn reported Galaxy has directly confirmed more than 450 BTC through victim reports and used those disclosures to identify other victims accounting for more than 730 BTC. Thorn said the team is withholding additional suspected funds until it can obtain stronger corroboration.

TRM Labs’ tracing places the loss in a similar range, estimating roughly 1,816 BTC moved from more than 5,200 addresses across four waves of activity. Ari Redbord, TRM’s global head of policy, cautioned that the figure may increase as more data and victim confirmations appear: “Investigators should expect the estimate to keep moving upward before it stabilizes.”

Some of the stolen funds have passed through cryptocurrency mixers, with reported transfers including 64 BTC and 200 ETH into mixing services. Those moves complicate recovery and attribution.

Analysts say the differences between tallies reflect the challenge of measuring losses from self-custody wallet breaches. Unlike an exchange hack, there is no central registry of affected accounts, so investigators rely on a mix of victim reporting, on-chain pattern recognition and conservative attribution to reduce false positives. Not all major blockchain investigators have published independent totals, and some analysts have declined to monitor the incident. Investigators expect the loss estimate to continue shifting until a wider set of victims come forward or additional on-chain links are firmly established.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author