Galaxy Research Traces $70M Coldcard Bitcoin Wallet Attack to 1,196 Drained Addresses
Key Takeaways
- •Galaxy Research traced the coordinated theft of 1,082.65 BTC worth roughly $70.2 million from 1,196 addresses to a single automated operator based on uniform transaction patterns.
- •The exploit targeted a seed generation vulnerability in Coldcard hardware wallets produced by Coinkite, affecting multiple device models including the Mk3, Mk4, Mk5, and Coldcard Q.
- •Stolen funds were consolidated into four Bitcoin addresses and have not been moved since the initial theft on July 30.
- •Coinkite CEO Rodolfo Novak publicly accepted responsibility for the firmware bug and acknowledged that the company's review process failed to detect the flaw before release.
- •Galaxy Research warns that future thefts may not follow the same onchain pattern and recommends users migrate to multisignature self-custody or trusted custodial services.

Galaxy Research has identified 1,196 Bitcoin addresses that were drained of 1,082.65 BTC — worth approximately $70.2 million — during a 41-minute window on July 30. According to the firm, the transactions took place between 01:10:20 UTC and 01:51:26 UTC across six Bitcoin blocks, occurring before Coinkite publicly disclosed a firmware vulnerability affecting certain Coldcard hardware wallets. Coldcard, produced by Coinkite, is a Bitcoin-only hardware wallet designed for air-gapped operation, a feature that has made it popular among self-custody users prioritizing key isolation. Galaxy Research reported no additional matching transactions over the preceding 30 days.
Onchain Pattern Linked the Transactions
Galaxy Research found that every transaction paid the same 30.0 sat/vB network fee and produced no change output. Researchers said that fixed fee distinguished the activity from normal Bitcoin consolidations and pointed to a single automated operator.
The report stated that 1,183 native SegWit addresses, seven BIP-49 addresses, and six BIP-44 addresses were drained — covering three distinct Bitcoin address derivation standards used across different wallet generations. Galaxy Research said that distribution was consistent with automated scanning across multiple wallet derivation paths.
Researchers also noted that the transactions appeared in batches rather than continuously. Three intervening blocks contained no sweep activity during the 41-minute period. Galaxy Research identified four Bitcoin addresses that received the stolen funds, adding that those holdings have not moved since the initial consolidation.
Firmware Bug Prompted Emergency Response
Coinkite first alerted users to an issue affecting seeds generated on Coldcard Mk3 devices running firmware version 4.0.1 and later. Seed generation vulnerabilities are among the most serious classes of hardware wallet flaws because they can compromise the cryptographic randomness underlying private keys, potentially allowing an attacker to recreate wallets without physical access to the device. The company subsequently expanded the advisory to include certain Mk4, Mk5, and Coldcard Q firmware versions while releasing emergency firmware updates.
Coinkite CEO Rodolfo Novak accepted responsibility for the firmware bug and issued an apology to users. He stated that the company's review process failed to detect the issue prior to release. Novak further suggested that artificial intelligence may have helped uncover the vulnerability, noting that AI-assisted code review can identify software weaknesses faster than traditional manual reviews.
Researchers Warn More Attacks Remain Possible
Galaxy Research cautioned that future attacks remain possible if users keep funds in affected single-signature Coldcard addresses. Single-signature wallets require only one private key to authorize transactions, meaning that a compromised seed alone is sufficient for an attacker to sweep funds. However, the firm stressed that subsequent incidents may not follow the same onchain transaction pattern.
According to Galaxy Research, the identifiable pattern only links the initial attacker. It does not enable detection of future thefts, as those transactions could appear identical to legitimate wallet transfers.
The firm urged users to move funds into trusted custodial services or multisignature self-custody configurations, which require multiple independently generated keys to authorize any transaction. Coinkite also advised users to install updated firmware, generate a new seed, test the wallet with a small transfer, and retain old backups until migration is complete.