Anagram Digital What we do

On-chain forensics

Coldcard owners and thieves race to drain vulnerable BTC

A $2.3bn mass migration on-chain

The losses reported so far run from roughly $89 million to $116 million. As we demonstrate below, the full extent of the Coldcard-related migration is on another order entirely, around $2.3 billion.

This analysis builds on the excellent work Galaxy Research has done mapping the Coldcard exploit. They followed the money on-chain and grouped the thefts into distinct waves: Wave 1, roughly 1,083 BTC drained from 1,196 addresses between 01:10 and 01:51 UTC on July 30; then Wave 2 and Wave 3 over the days that followed. They put confirmed losses at somewhere between 1,367 and 1,816 BTC across more than 4,500 addresses, and identified at least fifteen separate operators behind the sweeps. It is careful, fingerprint-driven forensic work, and it is the foundation this piece stands on.

The Coldcard disclosure set off a 10× spike in dormant coin sweeps

About 46,000 qualifying sweeps in the disclosure week against a ~4,000 baseline: roughly 42,000 excess transactions moving some 36,000 BTC, around $2.3 billion.

Qualifying sweeps per week: a dormant coin in a single address matching Coldcard's features to one fresh, unlabeled address. Source: Anagram Digital analysis of the Bitcoin blockchain. Four weekly windows, Apr – Aug 2026.

Research by
Anagram Digital
anagram.digital/coldcard-migration

Galaxy answered who did it and how much was stolen. We set out to measure something they did not: the full size of the event on-chain. The identified theft is only the visible tip of it. The moment a flaw like this becomes public, the thieves race to drain wallets and the owners race to empty their own into safety, and both leave the same basic footprint: a dormant coin in a single address matching Coldcard's features to one fresh, unlabeled address. We built a detector for exactly that footprint and ran it across the disclosure week and three ordinary weeks before it. The full method is at the end of this post.

The result is the chart above. A normal week produces about 4,000 of these sweeps. The disclosure week produced more than 46,000. Strip out the ordinary background and you are left with roughly 42,000 excess transactions moving about 36,000 BTC, on the order of $2.3 billion, the great majority of it owners relocating their own coins rather than losing them. The heist that made headlines is real, but it is a small fraction of what actually moved.

The robbery and the escape look the same

Once you have the full population of sweeps, you can group them by where they landed and count how many each receiving address pulled in. The distribution is lopsided in a way that tells the story on its own. 98.5% of the receiving addresses got exactly one sweep. One old wallet in, nothing else. That is the signature of an owner who moved their stack once and stopped, and it is also the signature of a thief who cracked one wallet and did not bother to consolidate. Structurally, they are the same transaction. There is no feature on-chain that separates them.

Higher sweep counts, we assess, more likely mean theft than fleeing owners

Sweeps receivedReceiving addressesShareBTC collected

The long tail (addresses receiving only one sweep) is fleeing owners and likely some thieves: structurally identical and impossible to tell apart. Only the > 20 cap is highly suggestive of theft: 22 addresses holding 1,144 BTC, 73% of it already forwarded onward within the week.

42,126 receiving addresses, disclosure week (Jul 30 – Aug 6, 2026), grouped by how many sweeps each collected. Source: Anagram Digital analysis of the Bitcoin blockchain.

Research by
Anagram Digital
anagram.digital/coldcard-migration

The theft only becomes legible at the far end of the distribution, where a single address is collecting sweeps by the hundred. Nobody funnels four hundred strangers' coins into one address by accident. Twenty-two addresses cleared twenty or more sweeps each; together they took in about 1,144 BTC, three quarters of which was already forwarded onward before the week was out. That is operator behavior. Our read is that fan-in is the tell: the more sweeps an address collected, the more likely it is theft rather than an owner fleeing. It is an assessment, not a proof, and we would not state it any harder than that.

The week, block by block

Plot every Bitcoin block of that week by how many sweeps it carried and the sequence of the attack falls out cleanly. The professionals struck first, before almost anyone knew: Wave 1 fired at 01:10 UTC on July 30, hours before the vulnerability was public. Coldcard's own warning did not go out until 6:50pm Eastern that evening. Only then does the broad rise begin, peaking the next day as owners and copycats pour in.

The heists fired first. The crowd came the next day.

Every block during the Coldcard week, by the number of qualifying dormant coin sweeps it carried.

One bar per Bitcoin block, Jul 30 – Aug 5, 2026. Source: Anagram Digital analysis of the Bitcoin blockchain.

Research by
Anagram Digital
anagram.digital/coldcard-migration

The timing points to theft waves no one has flagged yet

Block 960359 is the clearest example. At 06:38 UTC on July 31 it carried 435 sweeps worth 610 BTC, and not one of them went to a known operator. Every sweep landed in a different address, 434 of them, with no explicit connection to one another. It stands alone as a single tower, far above the blocks on either side. We marked it Wave 1.5 because we cannot yet say what it is.

What we can say is that it did not happen by chance. If these sweeps were independent events arriving at a steady rate, the odds of 435 landing in one ten-minute block are vanishingly small: even at the most generous local rate, the surrounding two hours, the probability is about one in 10⁶⁹ (the upper-tail p-value of a Poisson distribution fit to that rate). So the timing is not random. While we cannot rule out a benign explanation, the most apparent reading is a coordinated movement carried out by a single actor.

And 960359 is not alone. Around a dozen other blocks that week carry the same signature: a sudden burst of sweeps into many unconnected addresses, with no known operator among them, each standing well above its neighbors. Every one is a candidate for a theft wave that has not yet been attributed.

That gap is the point. The amount actually stolen sits somewhere between the reported $89 to $116 million estimates and the $2.3 billion that moved in total, most likely nearer the lower end. The rest, the great majority, was owners rescuing their own coins. As the receiving addresses begin to consolidate and move their BTC, the links between these transactions will come into focus. We will keep watching the data as it evolves, and will publish a follow-up as that picture sharpens.

Methodology

The detector runs in two stages. The first defines the features of a Coldcard wallet. The second defines the population of qualifying transactions: migrations from a probable Coldcard wallet into a newly created wallet. A qualifying sweep, in plain terms, is a coin dormant 6+ months moving from a single address to one fresh, unlabeled address.

The Coldcard address. A single-signature address of one of the four types a Coldcard can generate, legacy (P2PKH, 1...), nested SegWit (P2SH, 3...), native SegWit (P2WPKH, bc1q...), or Taproot (P2TR, bc1p...), whose change has always returned to the same address, and that was first used at least six months ago.

The transfer. A transaction inside the window spending from exactly one address matching that fingerprint into exactly one receiving address, where the receiving address had no activity before the window and is not attributed to any known entity.

Follow the research

We publish original on-chain research like this. Leave your email and we will send new analysis when it is published. No marketing, and you can unsubscribe anytime.

Work with Anagram Digital

If you have a matter where the on-chain facts have to be right, or research you need done, tell us in a line and we reply personally. Anagram takes on bespoke engagements for counsel, financial institutions, and funds: litigation support and expert witness work, flow-of-funds tracing, custom research, and due diligence of the kind shown here. Write max@anagram.digital.