Coldcard Firmware Vulnerability Drains $70M Bitcoin From 1,196 Wallets

Editorial illustration for: Galaxy Research Expands Coldcard Bitcoin Loss Estimate to $70 Million

In brief

  • Galaxy Research identified 1,082.65 Bitcoin lost across 1,196 addresses in 41-minute window on July 30
  • Stolen funds valued at approximately $70.2 million at time of transactions
  • Coinkite hotfix released but does not protect seeds from vulnerable firmware
  • Affected users advised to move funds to new seed immediately

Galaxy's Expanded Analysis

Galaxy Research traced the Bitcoin movements between 1:10 AM and 1:51 AM UTC on July 30 across blocks 960,183 to 960,191. The identified transactions shared a pattern, including identical 30 satoshis per virtual byte fees and no change output. This fingerprint allowed researchers to link the movements to a single coordinated attack.

The scale now dwarfs an earlier preliminary analysis. AnchorWatch CEO Rob Hamilton estimated 594.48 Bitcoin, worth around $38 million, moved across 500 transactions within a three-block window. Galaxy's work more than doubled that figure.

Critically, the Bitcoin movements occurred approximately 30 hours before Coldcard published its first security advisory. That lag meant affected users had no warning before their wallets were compromised.

Coinkite's Response and Limitations

Coinkite co-founder Rodolfo Novak said the company takes responsibility for the firmware bug and is working to determine the full scope of the issue.

The company moved quickly. Coinkite released a hotfix to remove the software fallback path that enabled the attack. Yet Novak was candid about the update's scope. "The update does not protect seeds generated on vulnerable firmware," he said.

That distinction matters. Users who generated seeds on vulnerable hardware remain exposed. Novak advised them to move their funds to a new seed immediately.

Fingerprint Uncertainty

Galaxy Research noted that future attacks against Coldcard-generated addresses may not follow the same fingerprint. That means the 1,196-address cluster they identified could undercount the total damage if attackers diversified their fee patterns or outputs. The analysis is precise but may not capture every victim.

For now, the $70.2 million figure stands as the most comprehensive estimate of the incident's scope.