Bitcoin Losses From Coldcard Vulnerability Surge to $70M, Galaxy Research Warns

Table of Contents

TL;DR

  • Galaxy Research estimates that attackers drained more than 1,000 BTC, worth approximately $70 million, from nearly 1,200 Bitcoin addresses linked to a firmware vulnerability affecting Coldcard hardware wallets.
  • Coinkite acknowledged the firmware issue, expanded the list of affected devices, and released emergency updates, urging users to migrate funds to newly generated wallets as soon as possible.
  • Despite the incident, hardware wallets remain one of the safest methods for long-term Bitcoin self-custody when users keep firmware updated and follow recommended security practices.

Bitcoin losses linked to the Coldcard vulnerability have climbed to approximately $70 million, according to Galaxy Research, after investigators connected more than 1,000 BTC stolen from nearly 1,200 addresses to a flaw affecting several firmware versions of the popular hardware wallet. The incident has renewed attention on wallet security while reinforcing the importance of timely firmware updates and responsible self-custody.

Bitcoin Coldcard Vulnerability Prompts Emergency Response

Galaxy Research reported that the compromised addresses lost a combined 1,082.65 BTC during a short period on July 30. According to the firm’s blockchain analysis, the transactions followed a consistent pattern indicating they were likely executed by the same attacker. Researchers noted that the movement of funds closely resembled ordinary wallet transfers, making the exploit difficult to detect without detailed forensic analysis.

Shortly before Galaxy published its findings, hardware wallet manufacturer Coinkite warned customers that seeds generated on certain Coldcard devices could be exposed because of a firmware bug. The company initially identified Coldcard Mk3 units running firmware version 4.0.1 or later before expanding the advisory to selected Mk4, Mk5 and Coldcard Q firmware releases.

Coinkite released emergency firmware updates and advised affected users to generate a new seed phrase, transfer their Bitcoin to fresh addresses, and verify the migration with a small test transaction before moving larger balances. The company also recommended keeping the previous backup until the migration process is fully completed.

Galaxy Research estimates that attackers drained more than 1,000 BTC, worth approximately $70 million, from nearly 1,200 Bitcoin addresses linked to a firmware vulnerability affecting Coldcard hardware wallets.

Bitcoin Coldcard Vulnerability Highlights Security Best Practices

Coinkite CEO Rodolfo Novak accepted responsibility for the flaw, stating that the company’s internal review process failed to identify the issue before deployment. He also suggested that advances in artificial intelligence could accelerate the discovery of software vulnerabilities, allowing attackers to examine publicly available code more efficiently than in previous years.

Galaxy Research warned that additional attacks remain possible if users continue relying on vulnerable seed generations. The research firm emphasized that the transaction pattern identifies the observed attacker but does not represent every possible exploitation method involving the firmware bug.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews