TL;DR
- Galaxy Research estimates that attackers drained more than 1,000 BTC, worth approximately $70 million, from nearly 1,200 Bitcoin addresses linked to a firmware vulnerability affecting Coldcard hardware wallets.
- Coinkite acknowledged the firmware issue, expanded the list of affected devices, and released emergency updates, urging users to migrate funds to newly generated wallets as soon as possible.
- Despite the incident, hardware wallets remain one of the safest methods for long-term Bitcoin self-custody when users keep firmware updated and follow recommended security practices.
Bitcoin losses linked to the Coldcard vulnerability have climbed to approximately $70 million, according to Galaxy Research, after investigators connected more than 1,000 BTC stolen from nearly 1,200 addresses to a flaw affecting several firmware versions of the popular hardware wallet. The incident has renewed attention on wallet security while reinforcing the importance of timely firmware updates and responsible self-custody.
We mapped the flow of funds for the Coldcard vulnerability based on the pattern identified by engineers at Block and shared by @clay_garrett
1,196 addresses drained in full for 1,082.65 BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC on Jul 30 — a 41-minute window, blocks… pic.twitter.com/q785paZvMQ
— Galaxy Research (@glxyresearch) July 31, 2026
Bitcoin Coldcard Vulnerability Prompts Emergency Response
Galaxy Research reported that the compromised addresses lost a combined 1,082.65 BTC during a short period on July 30. According to the firm’s blockchain analysis, the transactions followed a consistent pattern indicating they were likely executed by the same attacker. Researchers noted that the movement of funds closely resembled ordinary wallet transfers, making the exploit difficult to detect without detailed forensic analysis.
Shortly before Galaxy published its findings, hardware wallet manufacturer Coinkite warned customers that seeds generated on certain Coldcard devices could be exposed because of a firmware bug. The company initially identified Coldcard Mk3 units running firmware version 4.0.1 or later before expanding the advisory to selected Mk4, Mk5 and Coldcard Q firmware releases.
Coinkite released emergency firmware updates and advised affected users to generate a new seed phrase, transfer their Bitcoin to fresh addresses, and verify the migration with a small test transaction before moving larger balances. The company also recommended keeping the previous backup until the migration process is fully completed.


Bitcoin Coldcard Vulnerability Highlights Security Best Practices
Coinkite CEO Rodolfo Novak accepted responsibility for the flaw, stating that the company’s internal review process failed to identify the issue before deployment. He also suggested that advances in artificial intelligence could accelerate the discovery of software vulnerabilities, allowing attackers to examine publicly available code more efficiently than in previous years.
Galaxy Research warned that additional attacks remain possible if users continue relying on vulnerable seed generations. The research firm emphasized that the transaction pattern identifies the observed attacker but does not represent every possible exploitation method involving the firmware bug.





Be the first to comment