1,983 BTC Swept in 22 Hours.
The On-Chain Forensics.

⚠ Notice 1,983 BTC reflects our Tier 1 verified total across confirmed attacker addresses. External sources (Galaxy, Block) independently confirm 1,405–1,719 BTC. Our heuristic upper bound (including unverified patterns) is 3,138 BTC. Data last updated: —
—
Verified BTC Stolen
—
UTXOs Swept
4
Verified Waves
—
Current USD Value
HOLDING
Fund Status
Cross-validated with Galaxy Research · Chainalysis · Block · Community reports

The Timeline

Jul 30, 01:10 UTC

Wave 1 Begins

An automated script begins sweeping 1,195 vulnerable wallets at 30 sat/vB. Funds are sent to a handful of shared collector addresses.

Jul 31, 04:54 UTC

Attacker Adapts (Wave 2)

Community scripts attempt to frontrun the thefts. The attacker returns using RBF (Replace-By-Fee) and 50.2 sat/vB to bypass them.

Jul 31, 12:23 UTC

Evasion Pivot (Wave 3)

Realizing shared destinations are being tracked, the attacker shifts to sending every sweep to a unique P2WSH vault, paying exactly 201 sat/vB across 1,626 transactions.

Jul 31, Later

Firmware Fix Released

Coinkite releases firmware updates (v4.2.0, v5.6.0, v1.5.0Q) patching the RNG fallback flaw. The community scrambles to notify vulnerable users.

Aug 1+

Subsequent Waves

Independent researchers track additional smaller waves targeting remaining dust and utilizing diverse laundering strategies.

ACT 2 · THE SWEEP TIMELINE ═══════════════════════════════════════════════════════ -->

The Attack Unfolded in 22 Hours

In 42 minutes, an automated script swept 1,990 BTC. The next 21 hours swept 148 more.

The Attacker Evolved

Wave 1: shared collectors, easy to track. Wave 3: 1,626 unique vaults. The attacker adapted in real time.

Here's what happened: In Wave 1, the attacker sent stolen funds to a few shared addresses, which were easy to track. Once the community noticed, the attacker adapted. By Wave 3, they started sending each victim's funds to a brand new, unique address. The only clue left was the network fee: they paid exactly 201.0 sat/vB across 1,626 separate transactions, even when normal fees were around 3 sat/vB. This proves a single automated script was running the attack.

Community-Reported Waves

Independent researchers (Community reports) identified 6 additional waves targeting smaller balances and using diverse laundering techniques. We are tracking these but they are not included in our verified Tier 1 totals yet.

Four Exit Routes — None Fully Successful

Chainalysis identified four distinct laundering pipelines used by multiple independent attackers. Over $35M remains dormant.

Type 1: Holding in Cold Storage

Sent to large cold storage wallets. Over $35M is just sitting there unspent.

Type 2: Moved to Other Chains

Moved to Ethereum and other chains, then laundered through TornadoCash.

Type 3: Sent to Exchanges

Sent to crypto exchanges through intermediary wallets.

Type 4: Mixed via CoinJoin

Mixed using Wasabi Wallet to hide the transaction trail.

Victim Profile

Long-term holders were disproportionately hit. The median victim held their coins for 3.5 years before losing them.

3.5 Years
Median Time Held
88%
Coins Held > 1 Year
1.02 BTC
Median Victim Loss

Victim Balance Distribution

Loading victim distribution data…

Coin Age (Time Held)

Loading coin age data…

The Top 5% Lost 60% of All BTC

This was not a uniform attack. A tiny fraction of long-term "whales" accounted for the vast majority of the stolen value, underscoring the severity of the flaw for early adopters.

Where Are The Coins?

Five verified consolidation addresses hold the majority of stolen funds. None have moved.

Tier 1 verified total held across all consolidation addresses — BTC
These numbers are minimums. In Wave 3, the attacker used a unique wallet for every victim, making it hard to track everything. Our system found an additional — BTC that likely belongs to the attacker. How addresses are identified →
Want to trace the fund flows yourself?
Our interactive transaction graph lets you explore every sweep, cluster, and vault visually — no LLM required.
Open Graph Explorer

Check Your Exposure

We check your address locally on your device against our database of 4,925+ compromised addresses. Your address is never sent to our servers.

Never enter a seed phrase, private key, or passphrase into this page or any other. No legitimate tool asks for one.

Is Your Coldcard Affected?

Select your device details below to check if your wallet seed is vulnerable. If it is, updating firmware is not enough — you must move funds to a newly generated wallet.

The Coinkite advisory is the authority on remediation. 72-bit entropy on newer models is below the 128-bit threshold, so moving funds is strongly recommended even if dice were used.

Cross-Validation

Every number on this dashboard is triangulated against independent research. Here's how.

Galaxy Research (Alex Thorn)

Verified 1,719 BTC stolen from direct victim reports. Confirmed demographic targeting: high net-worth individuals with multi-year dormant coins.

Chainalysis

Identified four distinct laundering taxonomies (Consolidation, Cross-chain, CEX, CoinJoin).

Community Reports

Identified 10 waves of automated sweeps grouped by block height.