Stay connected with KayaToday, follow us on Instagram and Facebook for the latest news and reviews delivered straight to you.
When a centralised exchange gets hacked, investigators can pull a complete list of affected accounts and arrive at a precise loss figure within days. The Coldcard attack is a different kind of problem entirely, and the gap between what analysts can confirm and what they suspect tells you something important about the structural limits of tracing theft from self-custody wallets.
Three weeks into the investigation, blockchain analytics firms are publishing figures that diverge by hundreds of Bitcoin. CryptoQuant puts confirmed losses at 1,432 BTC. Galaxy Research sets its high-confidence minimum at 1,730 BTC. TRM Labs estimates attackers drained roughly 1,816 BTC from more than 5,200 addresses across four separate waves. All three figures are defensible. None of them is definitive. That is not a failure of analysis. It is a feature of how self-custody theft works.
Why victim reports drive the count more than blockchain data does
The core difficulty is that there is no master ledger of Coldcard users. Unlike a hacked exchange, which holds customer records and can identify every affected account, a hardware wallet manufacturer does not know who owns which wallet or how much Bitcoin sits inside it. Investigators are therefore working backwards, using victim disclosures to anchor their estimates and then extrapolating outward through on-chain patterns.
Galaxy’s Alex Thorn explained the methodology to Cointelegraph directly. Galaxy has confirmed more than 450 BTC through victim reports submitted to the firm. Those same reports, however, have allowed analysts to identify additional victims who had not yet come forward, pushing the corroborated total beyond 730 BTC. Thorn said the firm is deliberately withholding a further tranche of suspected losses because the corroborating evidence is not yet strong enough to publish with confidence. “We are still withholding many more BTC we suspect but for which we lack sufficient corroboration,” he told Cointelegraph.
TRM Labs is working from a similar methodology and arriving at a similar range. The firm’s global head of policy, Ari Redbord, told Cointelegraph that its independent tracing aligns with Galaxy’s figures, and he was blunt about the trajectory: “Investigators should expect the estimate to keep moving upward before it stabilizes.”
CryptoQuant’s stricter floor and why it matters
CryptoQuant is taking a more conservative position, and its reasoning is worth understanding rather than dismissing as simply cautious. The firm’s head of research, Julio Moreno, told Cointelegraph that CryptoQuant begins with public victim disclosures, including wallet addresses or transaction IDs, and cross-references those against known on-chain signatures from the attack before adding any figure to its tally.
The reason for that discipline is the risk of false positives. On-chain pattern matching can identify wallets that look like they were affected by the same attack, but “looking like” is not the same as confirmation. If CryptoQuant were to count every wallet that fits the pattern, it could inadvertently inflate the total by including wallets that were drained through an entirely separate vulnerability or user error. Moreno was explicit about the epistemological limit this creates: “Because the stolen Bitcoin belonged to individuals and not to a centralized entity, like an exchange, we can only confirm what each victim publicly discloses.”
His 1,432 BTC figure is therefore best understood as a floor rather than an estimate of the true total. It will rise as more victims come forward with verifiable evidence. It will not fall. “Knowing the total BTC stolen is difficult, and it will always be an estimation,” Moreno said.
What the methodology gap reveals about self-custody risk
The divergence between firms is not a dispute about facts. It is a dispute about methodology, specifically about how much inferential weight to place on on-chain patterns when direct victim confirmation is unavailable. Galaxy and TRM Labs are willing to publish higher figures because they have developed corroboration frameworks they trust. CryptoQuant is publishing a lower figure because it is not yet satisfied that on-chain inference alone meets its evidentiary standard. Both approaches are rational responses to the same underlying problem.
That problem is structural. Self-custody is the ideological core of Bitcoin ownership, the principle that individuals hold their own keys and do not rely on intermediaries. The Coldcard attack does not undermine that principle, but it does expose a consequence that the community rarely discusses openly: when self-custody wallets are compromised at scale, there is no authority with a complete picture of the damage. Chainalysis told Cointelegraph it has not conducted an independent tally. Blockchain investigator ZachXBT has publicly said he has no plans to monitor the incident at all. The investigation is therefore fragmented across firms with different methodologies and different risk tolerances for publishing uncertain figures.
For retail investors in Malaysia and Singapore, where hardware wallet adoption has grown alongside broader crypto participation, the Coldcard case is a reminder that self-custody carries a specific kind of tail risk. Regulators including the Securities Commission Malaysia and the Monetary Authority of Singapore have consistently emphasised the importance of understanding custody arrangements before investing. The Coldcard investigation illustrates exactly why that guidance exists: when something goes wrong with a self-custody setup, the path to quantifying the damage, let alone recovering funds, runs almost entirely through the victim’s own willingness to disclose publicly and the investigator’s ability to corroborate what they find on-chain.
The final loss figure from the Coldcard attack will almost certainly be higher than any number currently published. What the investigation has already demonstrated is that the tools for measuring self-custody theft are improving, but they remain fundamentally dependent on victims coming forward. In a world where Bitcoin holders prize privacy above almost everything else, that dependency is not going away.
Read More: Standard Chartered Sees LINK Hitting $200 by 2030. Here Is What Has to Go Right