Coldcard stolen Bitcoin still parked: 87% unmoved after $114.7M exploit

Researchers at Galaxy Research say the majority of Coldcard stolen Bitcoin remains unmoved after an exploit tied to $114.7M in losses at the time of theft. Galaxy traced 1,789.28 BTC stolen from 8,865 addresses to the Coldcard incident. Coldcard stolen Bitcoin data shows 1,561 BTC (87.3%) is still sitting in attacker-controlled collection/holding addresses and has not been spent, with the first three identified attack waves showing the strongest “dormancy” signal. Galaxy estimates the current value of that still-held portion at about $138.8M. The analysis also highlights typical victim losses: the median address loss was 0.00152 BTC and the average was 0.20184 BTC, while median dormancy before theft was 3.2 years (mean 3.6 years). Galaxy notes that some later Coldcard stolen Bitcoin has started moving, using obfuscation methods such as CoinJoin and “peel chains,” which fragment funds and complicate attribution. The firm shared identified attacker addresses with exchanges, compliance providers, and law enforcement, and says continued monitoring could support future freezing if stolen funds reach centralized services. On the root cause, TRM Labs previously attributed the theft waves (starting July 30) to a firmware randomness problem: a March 2021 build configuration error weakened the randomness used to generate some Coldcard wallet seeds, potentially enabling brute-force key recovery. TRM Labs also says updating firmware does not fix already-created weak seeds—users must generate new seeds on secure hardware and move funds. Traders should treat this as a security and liquidity-information update: most stolen BTC is not flowing to markets yet, but ongoing tracing and potential future actions (freezes) could still affect sentiment.
Neutral
The news is unlikely to create immediate market shock because 87% of the Coldcard stolen Bitcoin is reported as still unmoved. With most stolen BTC parked in attacker-controlled collection/holding wallets and showing long dormancy, near-term sell-pressure from the exploit appears limited. However, the longer-term risk is not zero. As Galaxy continues mapping wallets and shares attacker addresses with exchanges and compliance/law enforcement, there is a plausible path to later freezing—an outcome that can reduce realized losses for victims but also adds an “headline risk” loop for sentiment. At the same time, Galaxy’s observation that later theft waves started moving via CoinJoin and peel chains suggests attackers may still probe liquidity over time, which can eventually translate into sell-side pressure. Historically, large hardware-wallet incidents often produce a short-lived volatility spike driven by fear, followed by stabilization once it becomes clear whether stolen funds are actively circulating. Here, the parked-balance finding tilts impact toward the stabilization side, hence a neutral overall classification.