Today’s Field Note

The Coldcard exploit is still active. Galaxy Research confirms over $100M in Bitcoin drained across three waves, with a suspected fourth wave that could push losses to $130M. Roughly 90% of stolen coin remains unmoved, so attackers are still sweeping. Layered on top, hardware wallet firms report a phishing surge: fake “coordinated hardware audit” emails steering holders to a cloned Coldcard site that installs remote-access software. This is the standard pattern where the exploit does the heavy lifting and the phishing wave mops up everyone who panics. If you hold on a Coldcard, treat any affected seed as compromised, not merely at risk.

Today’s Move

  • If your Bitcoin sits on a Coldcard, move it now to a freshly generated seed on a known-good device. Do not reuse the old seed anywhere.
  • Ignore every “hardware audit,” “mandatory firmware update,” or “coordinated review” email. Coldcard is not emailing you to move funds. Delete it.
  • Only reach Coldcard, Ledger, or Trezor sites by typing the domain yourself. No Google clicks, no email links (see the $36k fake-Ledger-Live loss this week).
  • Never enter a 24-word seed into any website or desktop prompt, ever, regardless of how official the “update” screen looks.
  • Watch the known drainer consolidation addresses tracked by Galaxy and arkm; set alerts so you see the moment the unmoved 90% starts flowing.

Resources

  • https://www.coindesk.com/tech/2026/08/04/coldcard-urges-users-to-move-bitcoin-as-active-wallet-exploit-continues
  • https://decrypt.co/374891/hardware-wallet-firms-warn-of-phishing-surge-as-coldcard-losses-near-130m
  • https://www.reddit.com/r/CryptoCurrency/comments/1veys9x/lost_36k_in_crypto_scam_on_fake_ledger_site/
  • Incident trackers (reference standard): Rekt leaderboard · SlowMist Hacked

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @ItsAlreadyPrice or subscribe via RSS.