Five cryptocurrency wallets contain approximately 83 percent of the Bitcoin stolen through a Coldcard hardware wallet vulnerability, according to analysis by CryptoQuant researcher Julio Moreno. The concentration amounts to roughly 1,127 BTC of approximately 1,357 BTC stolen through early August.

The Coldcard hack, which began circulating publicly on July 30, exploited a flaw in the company's hardware wallet to drain user funds. The theft triggered a broader security review across the hardware wallet industry and raised questions about whether centralized holding patterns among stolen funds could aid law enforcement or exchanges in identifying and freezing assets.

Coldcard is manufactured by Coinkite, a Canadian hardware wallet producer. The device is marketed to institutional and retail users seeking offline key storage. A vulnerability in Coldcard's firmware allowed attackers to extract private keys under certain conditions, according to disclosures that followed the initial breaches. The company issued a firmware update and published a security advisory but did not disclose an exact theft total.

CryptoQuant's analysis tracked the movement of stolen funds across the blockchain. The five wallets holding the majority of stolen BTC represent a concentration risk that typically makes law enforcement tracing more feasible than a scattered distribution would. Exchange deposit addresses have been flagged in some cases, though the majority of stolen funds appear to remain in unspent outputs.

MSB Intel

Estimates of total theft have varied. Some reports place losses at approximately 1,596 BTC, while others cite figures near 1,127 BTC. The discrepancy reflects challenges in attribution when a vulnerability affects multiple users simultaneously and some victims may not yet have disclosed their losses. At prices prevailing in early August, the stolen amount would represent roughly 60 million to 100 million dollars depending on the transaction count and timing.

Hardware wallet security has become a focal point for both institutional and retail crypto participants following breaches at Ledger and Trezor in prior years. Each incident has prompted manufacturers to release patches and clarifications about attack vectors. Coinkite's response included technical guidance on which device versions and firmware versions were affected and recommendations for affected users to move funds immediately.

The stolen BTC has moved minimally since the theft, indicating either secure cold storage on the attacker's side or a deliberate holding pattern pending market conditions. On-chain watchers have tracked these movements across the five primary addresses.