Galaxy Research Traces $70M Coldcard Bitcoin Wallet Attack to 1,196 Drained Addresses

Galaxy traced 1,082.65 BTC stolen from 1,196 Coldcard-linked addresses. Fixed transaction patterns linked the 41-minute attack to one operator. Coinkite issued emergency firmware updates after confirming the flaw. Galaxy Research said it identified 1,196 Bitcoin addresses drained of 1,082.65 BTC, worth about $70.2 million, during a 41-minute period on July 30. According to Galaxy Research, the transactions occurred between 01:10:20 UTC and 01:51:26 UTC across six Bitcoin blocks before Coinkite publicly disclosed a firmware vulnerability affecting certain Coldcard hardware wallets. The firm also said it found no additional matching transactions over the past 30 days. Onchain Pattern Linked The Transactions According to Galaxy Research, every transaction paid the same 30.0 sat/vB network fee and created no change output. Researchers said that fixed fee distinguished the activity from normal Bitcoin consolidations and pointed to a single automated operator. The report stated that 1,183 native SegWit addresses, seven BIP-49 addresses and six BIP-44 addresses were drained. Galaxy Research said that distribution matched automated scanning across multiple wallet derivation paths. Researchers also found that the transactions appeared in batches rather than continuously. Three intervening blocks contained no sweep activity during the 41-minute period. Meanwhile, Galaxy Research said four Bitcoin addresses received the stolen funds. It added that those holdings have not moved since the initial consolidation. Firmware Bug Prompted Emergency Response Coinkite first warned users of an issue affecting seeds generated on Coldcard Mk3 devices running firmware version 4.0.1 and later. The company later expanded the advisory to include certain Mk4, Mk5 and Coldcard Q firmware versions while releasing emergency firmware updates. Coinkite CEO Rodolfo Novak accepted responsibility for the firmware bug and apologized to users. He also said the company's review process failed to detect the issue before release. Novak further suggested artificial intelligence may have helped uncover the vulnerability. He said AI-assisted code review can identify software weaknesses faster than traditional manual reviews. Researchers Warn More Attacks Remain Possible Galaxy Research said future attacks remain possible if users keep funds in affected single-signature Coldcard addresses. However, the firm stressed that future incidents may not follow the same onchain transaction pattern. According to Galaxy Research, the identifiable pattern only links the initial attacker. It does not detect future thefts because those transactions could appear identical to legitimate wallet transfers. The firm urged users to move funds into trusted custodial services or multisignature self-custody setups. Coinkite also advised users to install updated firmware, generate a new seed, test the wallet with a small transfer, and retain old backups until migration finishes. The post Galaxy Research Traces $70M Coldcard Bitcoin Wallet Attack to 1,196 Drained Addresses appears on Crypto Front News. Visit our website to
Galaxy traced 1,082.65 BTC stolen from 1,196 Coldcard-linked addresses. Fixed transaction patterns linked the 41-minute attack to one operator. Coinkite issued emergency firmware updates after confirming the flaw. Galaxy Research said it identified 1,196 Bitcoin addresses drained of 1,082.65 BTC, worth about $70.2 million, during a 41-minute period on July 30. According to Galaxy Research, the transactions occurred between 01:10:20 UTC and 01:51:26 UTC across six Bitcoin blocks before Coinkite publicly disclosed a firmware vulnerability affecting certain Coldcard hardware wallets. The firm also said it found no additional matching transactions over the past 30 days. Onchain Pattern Linked The Transactions According to Galaxy Research, every transaction paid the same 30.0 sat/vB network fee and created no change output. Researchers said that fixed fee distinguished the activity from normal Bitcoin consolidations and pointed to a single automated operator. The report stated that 1,183 native SegWit addresses, seven BIP-49 addresses and six BIP-44 addresses were drained. Galaxy Research said that distribution matched automated scanning across multiple wallet derivation paths. Researchers also found that the transactions appeared in batches rather than continuously. Three intervening blocks contained no sweep activity during the 41-minute period. Meanwhile, Galaxy Research said four Bitcoin addresses received the stolen funds. It added that those holdings have not moved since the initial consolidation. Firmware Bug Prompted Emergency Response Coinkite first warned users of an issue affecting seeds generated on Coldcard Mk3 devices running firmware version 4.0.1 and later. The company later expanded the advisory to include certain Mk4, Mk5 and Coldcard Q firmware versions while releasing emergency firmware updates. Coinkite CEO Rodolfo Novak accepted responsibility for the firmware bug and apologized to users. He also said the company's review process failed to detect the issue before release. Novak further suggested artificial intelligence may have helped uncover the vulnerability. He said AI-assisted code review can identify software weaknesses faster than traditional manual reviews. Researchers Warn More Attacks Remain Possible Galaxy Research said future attacks remain possible if users keep funds in affected single-signature Coldcard addresses. However, the firm stressed that future incidents may not follow the same onchain transaction pattern. According to Galaxy Research, the identifiable pattern only links the initial attacker. It does not detect future thefts because those transactions could appear identical to legitimate wallet transfers. The firm urged users to move funds into trusted custodial services or multisignature self-custody setups. Coinkite also advised users to install updated firmware, generate a new seed, test the wallet with a small transfer, and retain old backups until migration finishes. The post Galaxy Research Traces $70M Coldcard Bitcoin Wallet Attack to 1,196 Drained Addresses appears on Crypto Front News. Visit our website to
FOMOGRAM SENTINEL GRAVITY TELEMETRY
The $70M attack on Coldcard wallets raises security concerns for Bitcoin holders, potentially leading to bearish sentiment.
Explore all verified news, research, and global sources for CRYPTO.