1,983 BTC Swept in 22 Hours.
The On-Chain Forensics.
The Timeline
ChronologyWave 1 Begins
An automated script begins sweeping 1,195 vulnerable wallets at 30 sat/vB. Funds are sent to a handful of shared collector addresses.
Attacker Adapts (Wave 2)
Community scripts attempt to frontrun the thefts. The attacker returns using RBF (Replace-By-Fee) and 50.2 sat/vB to bypass them.
Evasion Pivot (Wave 3)
Realizing shared destinations are being tracked, the attacker shifts to sending every sweep to a unique P2WSH vault, paying exactly 201 sat/vB across 1,626 transactions.
Firmware Fix Released
Coinkite releases firmware updates (v4.2.0, v5.6.0, v1.5.0Q) patching the RNG fallback flaw. The community scrambles to notify vulnerable users.
Subsequent Waves
Independent researchers track additional smaller waves targeting remaining dust and utilizing diverse laundering strategies.
The Attack Unfolded in 22 Hours
Cumulative BTC · Wave-annotatedIn 42 minutes, an automated script swept 1,990 BTC. The next 21 hours swept 148 more.
The Attacker Evolved
Our Core Attack WavesWave 1: shared collectors, easy to track. Wave 3: 1,626 unique vaults. The attacker adapted in real time.
Community-Reported Waves
Waves 5-10Independent researchers (Community reports) identified 6 additional waves targeting smaller balances and using diverse laundering techniques. We are tracking these but they are not included in our verified Tier 1 totals yet.
Four Exit Routes — None Fully Successful
Cross-Validated · ChainalysisChainalysis identified four distinct laundering pipelines used by multiple independent attackers. Over $35M remains dormant.
Type 1: Holding in Cold Storage
Sent to large cold storage wallets. Over $35M is just sitting there unspent.
Type 2: Moved to Other Chains
Moved to Ethereum and other chains, then laundered through TornadoCash.
Type 3: Sent to Exchanges
Sent to crypto exchanges through intermediary wallets.
Type 4: Mixed via CoinJoin
Mixed using Wasabi Wallet to hide the transaction trail.
Victim Profile
Victim ImpactLong-term holders were disproportionately hit. The median victim held their coins for 3.5 years before losing them.
Victim Balance Distribution
Coin Age (Time Held)
The Top 5% Lost 60% of All BTC
ConcentrationThis was not a uniform attack. A tiny fraction of long-term "whales" accounted for the vast majority of the stolen value, underscoring the severity of the flaw for early adopters.
Where Are The Coins?
Verified Attacker WalletsFive verified consolidation addresses hold the majority of stolen funds. None have moved.
Our interactive transaction graph lets you explore every sweep, cluster, and vault visually — no LLM required.
Check Your Exposure
Private & Secure CheckWe check your address locally on your device against our database of 4,925+ compromised addresses. Your address is never sent to our servers.
Never enter a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.
Is Your Coldcard Affected?
Interactive WizardSelect your device details below to check if your wallet seed is vulnerable. If it is, updating firmware is not enough — you must move funds to a newly generated wallet.
The Coinkite advisory is the authority on remediation. 72-bit entropy on newer models is below the 128-bit threshold, so moving funds is strongly recommended even if dice were used.
Cross-Validation
Community DataEvery number on this dashboard is triangulated against independent research. Here's how.
Galaxy Research (Alex Thorn)
Verified 1,719 BTC stolen from direct victim reports. Confirmed demographic targeting: high net-worth individuals with multi-year dormant coins.
Chainalysis
Identified four distinct laundering taxonomies (Consolidation, Cross-chain, CEX, CoinJoin).
Community Reports
Identified 10 waves of automated sweeps grouped by block height.