Top StoriesBearish
74
BTC

Coldcard Bitcoin Theft Hits $70M, Galaxy Analysis Shows

Galaxy Research’s on-chain analysis reveals that the Coldcard wallet firmware bug resulted in theft of over 1,082 Bitcoin ($70.2M) across 1,196 addresses. The incident, which occurred on July 30, exploited a software fallback path during seed generation. Coinkite has issued a hotfix and is investigating the full scope.

CointelegraphCointelegraph by Helen Partz

Quick Take

1

Galaxy Research traced 1,082.65 BTC (~$70.2M) stolen in Coldcard exploit.

2

The firmware bug allowed attackers to compromise generated seed phrases.

3

Coinkite released a hotfix but urges users to migrate funds to new seeds.

4

Future attacks may not share the same on-chain fingerprint pattern.

Market Impact Analysis

Bearish

The security breach may erode trust in hardware wallets and cause short-term selling pressure on Bitcoin, though the market is expected to absorb the impact.

Timeframeshort

Speculation Analysis

Factuality85/100
RumorsVerified
Speculation Trigger65/100
MinimalExtreme FOMO

Key Takeaways

  • Galaxy Research traced 1,082.65 Bitcoin stolen through a Coldcard firmware exploit — the revised loss now totals $70.2 million.
  • A software fallback bug during seed generation allowed attackers to compromise seed phrases and drain wallets.
  • Coinkite rushed a hotfix but warns it won't protect seeds created on vulnerable firmware — users must migrate funds to new seeds.
  • Future exploit patterns may not match this on-chain fingerprint, making detection harder, Galaxy warns.
Amount Stolen1,082.65 BTCAcross 1,196 addresses
Total Value$70.2 millionAt time of theft, July 30
Transaction Fee30 sat/vBIdentical across all attacks
Block Window960,183–960,1911:10–1:51 AM UTC

What Happened

The Coldcard hardware wallet suffered a critical breach on July 30, with attackers draining 1,082.65 Bitcoin — worth $70.2 million at the time — from 1,196 addresses. Galaxy Research identified the theft pattern across nine blocks in a 41-minute window, roughly 30 hours before Coinkite published its first security advisory. The exploit bypassed the wallet's secure seed generation by triggering a rarely used software fallback, enabling attackers to capture and later sweep funds from compromised seeds. Early estimates by AnchorWatch pegged losses at $38 million, but Galaxy's on-chain analysis more than doubled that figure. The incident is now the largest hardware wallet hack on record, shaking confidence in a product long considered a gold standard for cold storage.

The Numbers

Galaxy traced 1,082.65 BTC across 1,196 addresses, all drained within 41 minutes. Each transaction paid an identical fee of 30 satoshis per virtual byte and left no change outputs — a clean sweep pattern that made the theft instantly recognizable on-chain. The funds moved between 1:10 AM and 1:51 AM UTC, compressed into blocks 960,183 through 960,191. The $70.2 million haul is nearly double the initial $38 million estimate, which counted only 594 BTC. Galaxy warns that this on-chain signature may not repeat in future attacks, raising the stakes for detection.

Why It Happened

A firmware bug in Coldcard hardware wallets introduced an unintended software fallback during seed generation. Instead of relying solely on the secure hardware random number generator, the device could invoke a deterministic path that attackers learned to exploit. This allowed them to recreate seed phrases and access wallets. Coinkite co-founder Rodolfo Novak acknowledged the flaw and took responsibility. The company’s hotfix disables the fallback entirely, but seeds already generated on vulnerable firmware remain compromised. The bug underscores the persistent risk of complexity in hardware wallets, where even a minor code path can become a catastrophic attack vector.

Broader Impact

The Coldcard breach erodes trust in hardware wallets, long touted as the safest way to hold Bitcoin. Galaxy’s warning that future attacks may not share the same on-chain fingerprint means the industry faces a detection nightmare. If exploiters randomize fee rates or use coin joins, similar thefts could go unnoticed. This incident may trigger a wave of firmware audits across the industry and accelerate migration to multi-signature or passphrase-protected setups. For Bitcoin’s security narrative, the damage extends far beyond the $70 million lost — it exposes a systemic blind spot in seed generation that other wallets may share.

What to Watch Next

  • Coinkite’s ongoing investigation — any discovery of additional compromised seeds or expanded scope could escalate the crisis.
  • On-chain surveillance for new attack patterns that deviate from the 30 sat/vB, no-change signature.
  • User migration trends as holders abandon Coldcard for competing hardware wallets or move to multi-sig solutions.
Source: Cointelegraph

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Cointelegraph
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

⚖️
Regulatory UpdatesNeutral
52

Russia Extends Crypto Mining Ban to Moscow Until 2032

Russia's Resolution No. 936 extends cryptocurrency mining bans to Moscow and nearby regions from August 2026 through 2032, citing electricity concerns. The measure covers Moscow, the Moscow Region, and parts of Kursk Region, where 65 data centers currently operate with 734 MW combined capacity.

90% confidence
Aug 1, 2026, 10:23 AM UTC · Cointelegraph
Coldcard Theft Surges to $70M, Galaxy Research Shows | Bytewit