1,789.28 BTC and 87.3% Unmoved: Measuring the Loss
ChainCatcher and BlockBeats, citing Galaxy Research, reported that the Coldcard hardware-wallet attack involved 8,865 addresses and about 1,789.28 BTC, worth roughly $114.7 million at the time of theft. About 1,561 BTC, or 87.3%, remained in attacker-controlled addresses, while all bitcoin from the first three waves had not moved. Some later funds were routed through CoinJoin and peel-chain patterns. The dataset also included 221 victim reports covering 790.72 BTC, with a median reported loss of 1.04272 BTC.
CoinJoin and Peeling: Why the Trail Gets Harder
The numbers separate a tracked theft total from losses covered by submitted reports. Galaxy shared identified attacker addresses with exchanges, compliance firms and law enforcement, but attribution, control and future cash-out routes still require continued verification. A high unmoved share is both an unresolved risk and a possible detection window if funds enter a centralized intermediary. CoinJoin and small splits increase complexity but do not alone prove successful laundering.
After Address Sharing: What Determines the Freeze Window
A KYT-focused update should connect victim addresses, suspected attacker wallets, mixing entry points and centralized services in one time-stamped graph. Statuses should distinguish stolen, moved, exposed to a high-risk service and frozen. “Unmoved” is not recovery, and an analytics label should not be presented as a judicial finding. Readers should distinguish an observed balance from an inferred owner, and a transaction path from a proven motive. Later movements can strengthen or weaken the initial interpretation, so every update needs a timestamp and the same accounting scope. For publication, every numerical claim should retain its unit, reporting window and source attribution. Estimates, analytics labels and project statements belong in separate evidence tiers from directly observable transfers or completed trades. Search users benefit from explicit boundaries. The current data can describe size, timing and sequence, but it cannot reveal private hedges, ultimate beneficial ownership or legal intent unless another source provides that evidence. A later update should test the conclusion against new wallet activity, venue exposure and realized outcomes. The evidence should remain reproducible from the cited snapshot, with estimates visibly separated from confirmed amounts. This approach serves search intent while avoiding a trading recommendation or an unsupported claim about motive. A later update should test the conclusion against new wallet activity, venue exposure and realized outcomes. The evidence should remain reproducible from the cited snapshot, with estimates visibly separated from confirmed amounts. This approach serves search intent while avoiding a trading recommendation or an unsupported claim about motive. A later update should test the conclusion against new wallet activity, venue exposure and realized outcomes. The evidence should remain reproducible from the cited snapshot, with estimates visibly separated from confirmed amounts. This approach serves search intent while avoiding a trading recommendation or an unsupported claim about motive. A later update should test the conclusion against new wallet activity, venue exposure and realized outcomes. The evidence should remain reproducible from the cited snapshot, with estimates visibly separated from confirmed amounts. This approach serves search intent while avoiding a trading recommendation or an unsupported claim about motive. A later update should test the conclusion against new wallet activity, venue exposure and realized outcomes.