BitcoinColdcard Watch

How these addresses were identified

View source code

A flaw in Coldcard wallet firmware made some recovery seeds predictable, and in late July 2026 a thief began recreating those keys and emptying the wallets they controlled. This page sets out how the drained addresses on this site were identified, and where the method can be wrong.

The address list is a verified minimum. Every address on it was found and checked here, and more clusters almost certainly exist. The dashboard's other two views carry larger totals published by Galaxy Research, who confirm thefts by writing to the victims. Those are shown as a single figure with their name on it and no address list, because the addresses behind them are not public. Which standard a number is being read at is set out below.

This is not a blocklist

Every address here is published in full so the work can be checked. That is the point of the page. It also means this list can be copied into a screening or compliance system, and if that happens an address stops being a research finding and becomes a problem for whoever holds it, usually without them ever knowing why.

Stated plainly: this is not a screening feed and it has no measured false-positive rate. None can be measured. Nobody has tested whether any of these addresses was in fact generated with weak entropy, and the vendor's own advisory told every affected owner to move their coins in a way that produces the same shape a theft does. The reasoning below is set out so it can be argued with, not so it can be automated against people.

If an address here is yours, it comes off. No proof of identity is needed and nothing secret should ever be sent: the address and the transaction are enough to check it against the chain, and if the listing does not hold up the totals move with it. Report it here. That request is handled before anything else on this project.

How sure each figure is

The site publishes one number at three standards, and the toggle on the dashboard moves between them. Each standard names what the figure rests on and who can check it.

StandardWhat it rests onPublished as
Proven Two addresses were spent together in one transaction, which only somebody holding both keys can do. Arithmetic on the chain, and anyone can repeat it. Individual addresses
Converged The sweep matches the drain fingerprint and converges with hundreds of others, on a shared destination or on a fee constant no independent owner would land on. Shape alone never qualifies, because the vendor advisory told owners to produce the same shape. Individual addresses
Corroborated A cluster assembled here from block data lands within 3% of a per-incident figure published by someone working from victim reports. Two methods that share no data agree on one event. Weaker than proven, and anything published on it says so. Individual addresses
Attested A source that confirms thefts by writing to the victims publishes a total. Nothing here can check it, because those addresses stay private and always will. One figure, no addresses
Suspected The same source's own lower-confidence figure, which they say no victim has confirmed. One figure, no addresses

The first three standards produce the address list. The last two produce a number and nothing else, and the site keeps them apart from its own work, in the colour they are drawn in and in the totals they are counted against.

Why Galaxy Research's total is carried here

For six days this site published 1,366 BTC while the figure everywhere else was 1,596. Galaxy Research confirm a theft by corresponding with the victim, so their set includes losses whose addresses were never made public. A method that reads only the chain cannot reach those, so leaving the number off left this site 14% low.

Their figure is repeated across most of the coverage of this incident. Those outlets are reporting Galaxy's number rather than checking it, and at least one says so outright, so the repetition adds no weight of its own. What warrants carrying it is that their figures agree with this site's independent reconstruction everywhere the two can be compared.

ComparisonGalaxyMeasured here
Wave 3 total207.73 BTC, from victim reports, with no addresses or code published207.72947587 BTC across 293 vaults, reconstructed from block data alone. The two agree to about two thousand satoshis.
Start of wave 101:08 UTC on 30 July, read off their chart The first sweep on chain is at 01:10:20.
How long the coins satAn average of 3.18 years untouched before being sweptA median of 3.5 years across 150 victims from this site's own set. The oldest was funded five days after the vulnerable firmware shipped.
Whether anything has movedNo coin from waves 1, 2 or 3 has moved Every vault tracked here is still unspent, which is the one part of their work this site watches continuously.

A fifth comparison belongs outside that table, because it checks their arithmetic rather than agreeing with it independently: reading the thirteen owner-confirmed markers off their own chart gives 223.18 BTC, against the roughly 229 BTC their headline total implies is missing from this site. Their per-incident figures add up to their own total.

Four independent agreements and no disagreement is the warrant. It is also the limit. If Galaxy revise their total, the attested figure here is wrong until it follows, and no amount of reading the chain would reveal that, so a watcher reads their posts instead.

What the attested figure is and is not

The site stores their total and subtracts what it has verified itself, so the attested view shows this site's own addresses plus one aggregate figure standing for the rest. Publishing a new cluster shrinks that aggregate rather than adding to it. A remainder frozen at the moment it was written would double-count every address published afterwards, and an earlier version of this page did exactly that.

Anything already inside one of those totals is listed under it rather than added to it. An independent report of the same fourth wave Galaxy already count is a second reading of one event, and adding both produced a total no source claims.

This assumes their total covers everything verified here. Every comparison above supports that and none contradicts it, but if this site ever holds a theft their set misses, the aggregate shown is too small by that amount.

The aggregate is not watched for movement. The clock on the dashboard and the banner that fires when coins move both track the addresses this site verified, because those are the only ones it knows. Galaxy report that about nine coins in ten across the whole incident have not moved.

Telling a victim apart from a thief

Each theft is one transaction with one input and one output. The input address is the victim, because that is where the money leaves. The output is the attacker, because that is where it arrives. Nothing is inferred from the addresses themselves. Direction does the work. A transaction like this, one that empties an address completely, is called a sweep below.

The drains take one of two shapes, and which one decides what there is to watch. In the first, every sweep is pooled into one shared address, a collector, that then holds the coins. In the second there is no collector at all: each wallet is swept to its own address, so the money sits in as many places as there were victims. Either way the dashboard watches wherever the coins came to rest.

Two shapes: waves 1 and 2 pool every sweep into one shared address; waves 3 and 4 sweep each wallet to its own address.
Waves 1 and 2 pooled every sweep into one address; waves 3 and 4 gave each wallet its own. The second shape has no shared address to watch, which is why the first detector missed it.

Telling a theft apart from someone moving to safety

This is the part that cannot be proven from the chain alone. Four things appear in every sweep and rarely together otherwise:

No single mark settles it on its own. An owner rescuing coins one at a time, moving each coin in its own transaction to keep their histories separate, produces the same shape the tool does. What an owner cannot produce is convergence with hundreds of strangers, and there are two kinds of it in this incident. An address is listed on this site only when its sweep shows one of them, and never on shape alone.

Convergence of destination. Hundreds of sweeps land inside one window, every one paying the same fee rate regardless of what the network was charging, and every one paying into the same address. A rescue goes to the owner's own wallet, and a thousand separate owners cannot share one destination. The first, second and fifth clusters are listed on this test.

Convergence of fee. Wave 3 removed the shared destination deliberately, giving each drained wallet its own fresh address and then its own fresh vault of a different address type (P2WSH), 214 of them sharing nothing, which is why this site missed the wave for two days. What it did not remove is the fee. Its 215 sweeps all paid within a hair of 201 sat/vB (satoshis per unit of transaction size, which is how Bitcoin fees are priced) while the network was charging under 3, and a rate that constant across transactions sharing no address is a number hardcoded in a script rather than 215 strangers independently choosing the same urgent fee. Sixteen further chains matched the shape but paid scattered rates, and they were left off rather than published on shape alone.

Three further marks hold across that wave, and are set out here because the fee should not carry it alone. The oldest coin anywhere in the set was created in block 677,217, about two weeks after the vulnerable firmware shipped: nothing in the set predates the flaw, which is what a population of addresses generated by that firmware would look like. All 214 vaults are still unspent, where an owner who moves coins to safety goes on to use the wallet they moved to. And Galaxy Research reported a wave of this size in this window from their own separate analysis, which is harder to account for if these sweeps were owners rescuing their own coins.

What each cluster rests on

WhenSizeFee rateHow it was found
30 Jul
01:10–01:51
1,195 addresses
1,082.65 BTC
30.0 sat/vB Reported by researchers at AnchorWatch, Block and Galaxy. Reconstructed here independently; the total matched the published figure to the satoshi.
31 Jul
04:54–08:36
1,126 addresses
45.97 BTC
50.2 sat/vB Reported by Kevin Kelbie, past the end of Block's transaction scan. Verified here on-chain. Every input signals replace-by-fee (an optional wallet flag), which the earlier batch does not.
31 Jul
19:53
13 addresses
0.19 BTC
2.0 sat/vB Reported in a reply by @jmassu. Verified here: twelve single-input sweeps in one block, then a consolidation into an address that has not moved.
Added
07 Aug
16 addresses
0.03 BTC
2.0 sat/vBMatches the drain fingerprint and independently reported by lopp. Verified on-chain.

Three different hardcoded fee rates, and only the second batch signals replace-by-fee. That is either one operator changing their tooling or more than one operator working the same flaw. There is no way to tell from the chain, and this page does not claim to know.

How new clusters are found

Every block since the first drain is read and tested against the pattern above, and the scan keeps running forward as new blocks are mined. A cluster nobody has reported still surfaces here, because the search is over the chain itself rather than over a list of addresses somebody supplied.

Blocks come from a Bitcoin Core node directly, so the scan does not depend on a third party's API or rate limit. When a group of sweeps in a single block pays into one address at one identical fee rate, that address becomes a candidate. Each candidate is then checked for freshness, because an exchange processing withdrawals produces a similar-looking burst: one rejected candidate had 476,464 prior deposits, which no collector in this incident has.

Anything that survives both tests raises an alert for a person to examine. A false accusation against an exchange or an uninvolved wallet would be worse than a slow addition, so a human confirms every cluster before it appears.

Reports from the people who were robbed

The block scan starts from the chain and works outward, so it can only find a cluster that matches the pattern above. A theft that used a different tool, or that nobody has connected to the known operators, can stay invisible to it. The people who were actually robbed are the other source, and several of them have posted their own drained address in public.

So the reports are watched too. An agent reads the replies and quotes on the threads about this incident, the posts that link here, and a standing search for people describing a Coldcard theft, and it pulls any bitcoin address out of them. A tweet is only a lead. Every address it surfaces is checked against the chain before anything happens, because a post can name the wrong address, quote the thief's address rather than the victim's, or be mistaken.

That check decides what follows, on two levels:

This runs on an always-on server that stays watching around the clock, so a report posted in the middle of the night is checked within the hour. What it cannot reach: a private or deleted account, a report that shows the loss only in a screenshot with no address in the text, and any claim the chain does not support; none of those appear here, which is the same standard the rest of the page holds to.

What this cannot see

The detector now looks for two shapes rather than one, but both are still shapes. A thief who uses an address type other than single-signature native segwit, varies the fee from one sweep to the next, or spreads a theft thinly enough that no block holds a group would still not match it. Wave 3 is the worked example: removing the shared collector made every detector on this site blind to it until the fee constant was used instead. The freshness test is also a judgement, not a proof: it sorts by how much unrelated history an address carries, and an unusual case can land on the wrong side of that line.

An address can therefore be missing from this set for two different reasons: it was never drained, or the pattern failed to catch the theft. Because the checker cannot tell those apart, a result of not in the verified set leaves the question open rather than settling it.

The attested figure is the measure of how much this misses. Galaxy count roughly 7,300 drained addresses and this site has verified 4,584 of them, so about a third of the thefts in this incident are ones no method that reads only the chain has reached.

Where the trail ends

This site reads the Bitcoin blockchain and nothing else. That is the whole of what it can see, and it is worth saying plainly what falls outside it.

Coins that leave Bitcoin are gone from this page. A cross-chain bridge, a swap service, a stablecoin, an exchange that credits an account balance rather than an address: in every case the money continues somewhere this site has no view of, and the last thing recorded here is a deposit.

Coins that reach a service stop being followable even while they sit on Bitcoin. A business holding funds for thousands of customers pools deposits and pays withdrawals in batches, so one transaction can merge hundreds of unrelated people's coins or pay out to hundreds at once. After that, no output can be tied to any particular input by anyone reading the chain from outside. The tracing here stops at that point and records that a service was reached, rather than following every output, because following them means enumerating that business's customers and calling the result a trail.

This site does not name the service. Knowing which business a batch belongs to requires address labelling gathered off the chain, from companies that collect it commercially or from the businesses themselves. This project has none of it, and a guess would carry the same authority as a verified address while resting on nothing.

Nothing here reads the mempool, so a transaction is only seen once it is in a block.

Four methods that professional chain analysis uses are deliberately absent, all for one reason. Change-output heuristics, taint or dust analysis, timing correlation across services, and value-flow attribution all extend a trail by assigning probabilities. Each would let this site say more, and each would put a probable claim on the same page as a proven one, in the same typeface, about somebody's address. The list is published so it can be argued with, which means everything on it has to be checkable.

What a missing address means is unchanged: not on this list means this site did not find it, and every limit above is a reason it might not have.

What the checker actually does

The list of drained addresses is turned into one-way fingerprints (hashes) and shipped with the page. When an address is entered, the browser fingerprints it the same way and looks for a match locally. Nothing is transmitted and nothing is logged. If the list fails to load, the tool disables itself rather than reporting everything as clean.

Sources and how to check the work

Block data for the scanning comes from a Bitcoin Core node. Address balances and histories come from Blockstream's Esplora, with blockchain.info used to read many addresses in one request and mempool.space as the fallback and the source of the exchange rate. Figures that appeared in more than one source were compared before being published, and the totals here match the independently published ones to the satoshi.

Every address on this site links to a block explorer, so any claim can be checked without trusting the page. Vendor detail comes from the Coinkite advisory and Block's engineering analysis.

If you know of a drained address or a collection address that is missing here, it belongs in the set. A report from someone who was there still beats a pattern match.