TL;DR
- Galaxy Analysis estimates that attackers drained greater than 1,000 BTC, value roughly $70 million, from practically 1,200 Bitcoin addresses linked to a firmware vulnerability affecting Coldcard {hardware} wallets.
- Coinkite acknowledged the firmware subject, expanded the checklist of affected units, and launched emergency updates, urging customers emigrate funds to newly generated wallets as quickly as potential.
- Regardless of the incident, {hardware} wallets stay one of many most secure strategies for long-term Bitcoin self-custody when customers hold firmware up to date and comply with really helpful safety practices.
Bitcoin losses linked to the Coldcard vulnerability have climbed to roughly $70 million, in response to Galaxy Analysis, after investigators linked greater than 1,000 BTC stolen from practically 1,200 addresses to a flaw affecting a number of firmware variations of the favored {hardware} pockets. The incident has renewed consideration on pockets safety whereas reinforcing the significance of well timed firmware updates and accountable self-custody.
We mapped the circulate of funds for the Coldcard vulnerability primarily based on the sample recognized by engineers at Block and shared by @clay_garrett
1,196 addresses drained in full for 1,082.65 BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC on Jul 30 — a 41-minute window, blocks… pic.twitter.com/q785paZvMQ
— Galaxy Analysis (@glxyresearch) July 31, 2026
Bitcoin Coldcard Vulnerability Prompts Emergency Response
Galaxy Analysis reported that the compromised addresses misplaced a mixed 1,082.65 BTC throughout a brief interval on July 30. In accordance with the agency’s blockchain evaluation, the transactions adopted a constant sample indicating they had been doubtless executed by the identical attacker. Researchers famous that the motion of funds intently resembled odd pockets transfers, making the exploit troublesome to detect with out detailed forensic evaluation.
Shortly earlier than Galaxy printed its findings, {hardware} pockets producer Coinkite warned clients that seeds generated on sure Coldcard units might be uncovered due to a firmware bug. The corporate initially recognized Coldcard Mk3 items operating firmware model 4.0.1 or later earlier than increasing the advisory to chose Mk4, Mk5 and Coldcard Q firmware releases.
Coinkite launched emergency firmware updates and suggested affected customers to generate a brand new seed phrase, switch their Bitcoin to recent addresses, and confirm the migration with a small take a look at transaction earlier than transferring bigger balances. The corporate additionally really helpful protecting the earlier backup till the migration course of is absolutely accomplished.

Bitcoin Coldcard Vulnerability Highlights Safety Greatest Practices
Coinkite CEO Rodolfo Novak accepted accountability for the flaw, stating that the corporate’s inner evaluation course of did not determine the difficulty earlier than deployment. He additionally instructed that advances in synthetic intelligence might speed up the invention of software program vulnerabilities, permitting attackers to look at publicly obtainable code extra effectively than in earlier years.
Galaxy Analysis warned that extra assaults stay potential if customers proceed counting on weak seed generations. The analysis agency emphasised that the transaction sample identifies the noticed attacker however doesn’t signify each potential exploitation methodology involving the firmware bug.

