Coldcard's "Cold" Storage Turns Lukewarm as $114M Bitcoin Walks Out the Backdoor 🔑
Losses tied to a long-undisclosed firmware flaw in Coinkite's Coldcard hardware wallets have climbed to roughly $114 million, with researchers at Galaxy Research tracking four coordinated waves of theft against single-signature addresses created on vulnerable devices. Galaxy head of research Alex Thorn logged 1,367 BTC (about $88.6 million) across 4,585 addresses through three confirmed waves, then flagged a fourth on Monday that added an estimated 448.73 BTC ($28 million) across 709 addresses after a set of wrongly included multisig addresses was corrected. Some of the fourth-wave transactions remain in the mempool and have opted into replace-by-fee, and Galaxy has flagged roughly 600 suspected attacker addresses to federal investigators, compliance firms and cross-industry cyber investigators. The running total of about 1,816 BTC, near $114 million, has not yet been confirmed by Coinkite or law enforcement and rests on on-chain pattern matching.
The flaw stems from a March 2021 firmware build error that caused seed phrases on affected devices to be generated with far less randomness than intended, leaving private keys guessable. Coinkite co-founder Rodolfo Novak said the company "takes responsibility for the firmware bug" and released a hotfix to remove the software fallback path, but warned that the update does not protect seeds generated on vulnerable firmware and advised users to move funds to a new seed. Block's Bitcoin engineering team separately found that a firmware integration error routed random-number generation through a deterministic MicroPython fallback rather than the intended hardware source, with Mk2 and Mk3 devices adding no cryptographic entropy through that path; Coinkite's advisory covers Mk2 and Mk3 firmware from version 4.0.1 through 4.1.9, plus seeds generated on Mk4, Mk5 and Q devices before their fixed releases.
The earliest documented activity moved 1,082.65 Bitcoin, worth about $70.2 million at the time, across 1,196 addresses between 1:10 AM and 1:51 AM UTC on July 30 across blocks 960,183 to 960,191, about 30 hours before Coldcard published its first security advisory, according to Galaxy's Friday X post. Earlier preliminary analysis by AnchorWatch CEO and co-founder Rob Hamilton had estimated 594.48 BTC (around $38 million) across 500 transactions within a three-block window, and the transactions shared a pattern of identical 30 satoshis per virtual byte fees with no change outputs. Galaxy cautioned that future attacks against Coldcard-generated addresses may not follow the same fingerprint, and Thorn wrote that the sweeps appear deliberate and programmatic, possibly orchestrated with a large language model, with an average dormancy of 3.18 years before the stolen coins were moved.
Bitcoin's price barely moved during the panic, sitting at $62,724, down 0.7% over the past day per CoinGecko data, even as small holders rebalanced en masse. CryptoQuant head of research Julio Moreno reported that transfers of less than 1 BTC totaled 39,600 BTC (around $2.5 billion) on July 31, the highest since 39,900 BTC on November 16, 2022, days after FTX collapsed, while daily active addresses rose from 645,000 on July 30 to nearly a million on July 31, the highest since December 2024, with the jump concentrated in sending addresses. Sub-10 BTC exchange deposits reached 7,300 BTC ($459 million) on July 31, the most since February 6, and Moreno said people appeared to be "looking for safety," though he noted the link to the Coldcard breach was not certain. Several victims, including Canadian coach Jonathan Goodman, said they were caught out, with Goodman reporting that 18.25 BTC, worth about $1.6 million Canadian, was swept from his device on July 29 despite his keys being kept on a Coldcard in a safety deposit box that had never been connected to the internet.
Bloomberg Intelligence senior ETF analyst Eric Balchunas said on Aug. 2 that the incident strengthens the case for U.S. spot Bitcoin ETFs, writing "Yes, an ETF fixes this (and it is kinda ironic given some cold storage ppl label ETFs as 'paper bitcoin')." Kraken chief security officer Nick Percoco called the incident a "wake-up call for the entire hardware wallet industry," and affected users who still control the relevant keys may be able to broadcast a higher-fee replacement transaction to move funds to a secure wallet before the attacker's transaction is confirmed.
Mentioned Coins
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.