Coldcard Bitcoin Theft Hits $70M, Galaxy Analysis Shows
Galaxy Research’s on-chain analysis reveals that the Coldcard wallet firmware bug resulted in theft of over 1,082 Bitcoin ($70.2M) across 1,196 addresses. The incident, which occurred on July 30, exploited a software fallback path during seed generation. Coinkite has issued a hotfix and is investigating the full scope.
Quick Take
Galaxy Research traced 1,082.65 BTC (~$70.2M) stolen in Coldcard exploit.
The firmware bug allowed attackers to compromise generated seed phrases.
Coinkite released a hotfix but urges users to migrate funds to new seeds.
Future attacks may not share the same on-chain fingerprint pattern.
Market Impact Analysis
BearishThe security breach may erode trust in hardware wallets and cause short-term selling pressure on Bitcoin, though the market is expected to absorb the impact.
Speculation Analysis
Key Takeaways
- Galaxy Research traced 1,082.65 Bitcoin stolen through a Coldcard firmware exploit — the revised loss now totals $70.2 million.
- A software fallback bug during seed generation allowed attackers to compromise seed phrases and drain wallets.
- Coinkite rushed a hotfix but warns it won't protect seeds created on vulnerable firmware — users must migrate funds to new seeds.
- Future exploit patterns may not match this on-chain fingerprint, making detection harder, Galaxy warns.
What Happened
The Coldcard hardware wallet suffered a critical breach on July 30, with attackers draining 1,082.65 Bitcoin — worth $70.2 million at the time — from 1,196 addresses. Galaxy Research identified the theft pattern across nine blocks in a 41-minute window, roughly 30 hours before Coinkite published its first security advisory. The exploit bypassed the wallet's secure seed generation by triggering a rarely used software fallback, enabling attackers to capture and later sweep funds from compromised seeds. Early estimates by AnchorWatch pegged losses at $38 million, but Galaxy's on-chain analysis more than doubled that figure. The incident is now the largest hardware wallet hack on record, shaking confidence in a product long considered a gold standard for cold storage.
The Numbers
Galaxy traced 1,082.65 BTC across 1,196 addresses, all drained within 41 minutes. Each transaction paid an identical fee of 30 satoshis per virtual byte and left no change outputs — a clean sweep pattern that made the theft instantly recognizable on-chain. The funds moved between 1:10 AM and 1:51 AM UTC, compressed into blocks 960,183 through 960,191. The $70.2 million haul is nearly double the initial $38 million estimate, which counted only 594 BTC. Galaxy warns that this on-chain signature may not repeat in future attacks, raising the stakes for detection.
Why It Happened
A firmware bug in Coldcard hardware wallets introduced an unintended software fallback during seed generation. Instead of relying solely on the secure hardware random number generator, the device could invoke a deterministic path that attackers learned to exploit. This allowed them to recreate seed phrases and access wallets. Coinkite co-founder Rodolfo Novak acknowledged the flaw and took responsibility. The company’s hotfix disables the fallback entirely, but seeds already generated on vulnerable firmware remain compromised. The bug underscores the persistent risk of complexity in hardware wallets, where even a minor code path can become a catastrophic attack vector.
Broader Impact
The Coldcard breach erodes trust in hardware wallets, long touted as the safest way to hold Bitcoin. Galaxy’s warning that future attacks may not share the same on-chain fingerprint means the industry faces a detection nightmare. If exploiters randomize fee rates or use coin joins, similar thefts could go unnoticed. This incident may trigger a wave of firmware audits across the industry and accelerate migration to multi-signature or passphrase-protected setups. For Bitcoin’s security narrative, the damage extends far beyond the $70 million lost — it exposes a systemic blind spot in seed generation that other wallets may share.
What to Watch Next
- Coinkite’s ongoing investigation — any discovery of additional compromised seeds or expanded scope could escalate the crisis.
- On-chain surveillance for new attack patterns that deviate from the 30 sat/vB, no-change signature.
- User migration trends as holders abandon Coldcard for competing hardware wallets or move to multi-sig solutions.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.