Coldcard Firmware Vulnerability Drains $70M Bitcoin From 1,196 Wallets
In brief
- Galaxy Research identified 1,082.65 Bitcoin lost across 1,196 addresses in 41-minute window on July 30
- Stolen funds valued at approximately $70.2 million at time of transactions
- Coinkite hotfix released but does not protect seeds from vulnerable firmware
- Affected users advised to move funds to new seed immediately
Galaxy's Expanded Analysis
Galaxy Research traced the Bitcoin movements between 1:10 AM and 1:51 AM UTC on July 30 across blocks 960,183 to 960,191. The identified transactions shared a pattern, including identical 30 satoshis per virtual byte fees and no change output. This fingerprint allowed researchers to link the movements to a single coordinated attack.
The scale now dwarfs an earlier preliminary analysis. AnchorWatch CEO Rob Hamilton estimated 594.48 Bitcoin, worth around $38 million, moved across 500 transactions within a three-block window. Galaxy's work more than doubled that figure.
Critically, the Bitcoin movements occurred approximately 30 hours before Coldcard published its first security advisory. That lag meant affected users had no warning before their wallets were compromised.
Coinkite's Response and Limitations
The company moved quickly. Coinkite released a hotfix to remove the software fallback path that enabled the attack. Yet Novak was candid about the update's scope. "The update does not protect seeds generated on vulnerable firmware," he said.
That distinction matters. Users who generated seeds on vulnerable hardware remain exposed. Novak advised them to move their funds to a new seed immediately.
Fingerprint Uncertainty
Galaxy Research noted that future attacks against Coldcard-generated addresses may not follow the same fingerprint. That means the 1,196-address cluster they identified could undercount the total damage if attackers diversified their fee patterns or outputs. The analysis is precise but may not capture every victim.
For now, the $70.2 million figure stands as the most comprehensive estimate of the incident's scope.


