Galaxy Research Links 1,367 BTC Theft to Coldcard Mk3 Firmware Flaw Across 4,585 Addresses
Key Takeaways
- •Galaxy Research confirmed losses of 1,367.05 BTC worth approximately $88.6 million across 4,585 addresses, more than doubling earlier estimates.
- •The vulnerability originated from a predictable random number generator in Coldcard Mk3 firmware versions 4.0.1 and later, introduced in March 2021.
- •Attackers could enumerate weak wallet seeds offline and sweep funds from single-signature addresses without requiring physical access to the device.
- •The largest attack wave on July 30, 2026, resulted in the theft of 1,082.65 BTC valued at approximately $70.2 million within just 41 minutes.
- •Coldcard Mk4, Q, and Mk5 devices are unaffected, and users of compromised Mk3 wallets are advised to generate entirely new seeds on unaffected hardware models.

Galaxy Research has confirmed that 1,367.05 BTC, valued at approximately $88.6 million, was stolen through three coordinated attack waves targeting 4,585 addresses linked to a firmware defect in Coldcard Mk3 hardware wallets. Coldcard, manufactured by Coinkite, is a Bitcoin-only hardware wallet widely used in the self-custody community for its air-gapped design, making a seed-generation flaw of this magnitude particularly significant for users who rely on dedicated hardware for key storage.
The findings significantly exceed earlier estimates, which had placed losses at roughly 594 BTC across approximately 500 addresses. Galaxy's on-chain analysis more than doubled the initial figure, revealing a substantially broader and more systematic operation than previously understood.
Timeline and Attack Structure
The largest single wave occurred on July 30, 2026, during which attackers swept 1,082.65 BTC — approximately $70.2 million — in just 41 minutes.
According to Galaxy's analysis, the first two attack waves displayed nearly identical transaction characteristics, including hardcoded fees of 30 sat/vB and consistent batching patterns. This uniformity points to a single operator or, at minimum, a single toolkit. The third wave diverged from this pattern, suggesting either a different actor or a deliberate change in tactics.
The stolen Bitcoin has remained largely stationary since the attacks, concentrated in a small number of attacker-controlled addresses without significant movement. This contrasts with patterns often observed in large exchange hacks, where stolen funds are frequently routed through mixers or chain-hopping services shortly after theft.
Notably, the hardcoded 30 sat/vB fee rate used in the first two waves was between 30 and 75 times the median network fee at the time, indicating that the attackers were willing to pay a substantial premium to prioritize rapid transaction confirmation.
Root Cause: Predictable Random Number Generation
The vulnerability resides in Coldcard Mk3 firmware versions 4.0.1 and later, introduced in March 2021. The defect caused the device's random number generator to produce weak, predictable outputs, meaning the wallet seeds it generated were not genuinely random. An attacker with sufficient computing resources could enumerate possible seeds offline, match them to active addresses on the blockchain, and sweep funds from single-signature addresses without requiring physical access to the device. RNG failures are considered among the most severe classes of cryptographic vulnerabilities in cryptocurrency systems because they undermine the foundational layer of private key creation — every address derived from a weak seed is compromiseable regardless of other security practices.
Block's engineering team is credited with first publicly disclosing the RNG issue. Coinkite, the manufacturer of Coldcard, released an advisory approximately 30 hours after the initial sweeps began.
Scope and Affected Devices
Coldcard Mk4, Q, and Mk5 devices do not appear to be affected by the same flaw. Users who hold funds on compromised Mk3 wallets are advised to generate entirely new seeds on unaffected hardware models rather than simply transferring balances within the same device generation.
For anyone currently using a Coldcard Mk3 device running firmware version 4.0.1 or later, Galaxy's findings indicate that the current seed should be treated as potentially compromised. The recommended course of action is to migrate funds to a freshly generated wallet on unaffected hardware. Reviewing firmware version history and consulting Coinkite's advisory are practical first steps in assessing exposure. The incident adds to a broader history of hardware wallet vulnerabilities across the industry, including past RNG and secure chip issues identified in devices from multiple manufacturers, reinforcing the case for periodic seed rotation and hardware upgrades as standard custody hygiene.