Coldcard's loaded dice: $130M in $BTC drained from vaults that never touched the internet
Losses from a five-year-old firmware flaw in Coinkite's Coldcard hardware wallets have climbed to roughly $130 million, with Galaxy Research tracking about 2,055 $BTC across three confirmed waves, a suspected fourth wave and 14 smaller incidents that the firm said may reflect opportunistic attackers exploiting the same vulnerability. Galaxy's confirmed tally alone reached 1,596 $BTC stolen from approximately 7,300 addresses after 73 victims contacted its researchers; 90% of the stolen coins have not yet moved from attacker addresses, which Galaxy has shared with U.S. federal law enforcement, crypto exchanges and cyber-investigation firms. The research arm of Galaxy Digital first identified 1,196 addresses linked to the incident on July 30, when 1,082.65 $BTC, worth about $70.2 million at the time, moved across blocks 960,183 to 960,191 between 1:10 AM and 1:51 AM UTC, roughly 30 hours before Coldcard's first security advisory. The transactions shared a pattern of identical 30 sat/vB fees and no change outputs, though Galaxy cautioned that future attacks against Coldcard-generated addresses may not carry the same fingerprint.
The flaw stems from a March 2021 firmware build error that routed seed generation through a deterministic MicroPython fallback called Yasmarang instead of Coldcard's hardware random number generator. Coinkite co-founder Rodolfo Novak said in an X post on Friday that the company takes responsibility for the bug and is working to determine the full scope of the issue, and released a hotfix to remove the software fallback path while warning that the update does not protect seeds generated on vulnerable firmware; he advised users who generated seeds on vulnerable firmware to move their funds to a new seed. Block's Bitcoin engineering team found that a firmware integration error using #ifndef — a directive that checks whether a setting is defined rather than whether it is enabled — bypassed a safety check because Coinkite had defined the setting as zero. On Mk2 and Mk3 devices running firmware 4.0.1 through 4.1.9, the seed's starting value came from the chip's serial number and clock, leaving an estimated 40-bit search space; newer Mk4, Mk5 and Q models mixed in limited secure-element entropy, lifting them to roughly 72 bits. Coinkite's security advisory covers Mk2 and Mk3 firmware from version 4.0.1 through 4.1.9, plus seeds generated on Mk4, Mk5 and Q devices before their fixed releases.
On Monday, Galaxy Research head Alex Thorn flagged a likely fourth wave of 218 transactions affecting 462 potential victim addresses and moving around 388.9 $BTC, averaging 13.8 sweeps per block — about 45 times the rate observed in a pre-incident control window. After correcting a set that had wrongly included multisig addresses, Thorn put the wave at 709 addresses and 448.73 $BTC (around $28 million). Thorn wrote that the sweeps look deliberate and programmatic, probably orchestrated with a large language model, and cautioned that every single-signature Coldcard address created after the 2021 update will eventually be drained; stolen coins had sat untouched for an average of 3.18 years before being taken, underscoring that victims were long-term holders. Some transactions from the latest wave were sitting unconfirmed in the mempool and had opted into replace-by-fee, meaning holders who act quickly with a higher fee may be able to outbid the attacker before confirmation. None of the addresses hit in the first three waves were multisig.
The fallout has driven a sharp shift in on-chain behavior. CryptoQuant head of research Julio Moreno said transfers of less than 1 $BTC totaled 39,600 $BTC (around $2.5 billion) on July 31, the highest level since the 39,900 $BTC recorded on November 16, 2022, days after FTX failed, while daily active addresses rose from 645,000 on July 30 to nearly a million on July 31, the highest since December 2024, with the jump concentrated in sending addresses. Sub-10 $BTC exchange deposits hit 7,300 $BTC (about $459 million) that day, the most since February 6, and $BTC was trading at $62,724, down 0.7% over the past day, per CoinGecko data. Several victims, including Canadian coach Jonathan Goodman, who said 18.25 $BTC (about 1.6 million Canadian dollars) was swept from his device, reported moving coins to centralized exchanges such as Coinbase or Binance, or to freshly generated addresses — an inversion of the industry's "not your keys, not your coins" ethos. Bloomberg Intelligence senior ETF analyst Eric Balchunas wrote on Aug. 2 that the incident strengthens the case for U.S. spot Bitcoin ETFs, arguing that "an ETF fixes this" and noting the irony of some cold-storage users labeling such funds "paper bitcoin." Kraken chief security officer Nick Percoco called the incident a "wake-up call for the entire hardware wallet industry," and Galaxy Research's estimate of confirmed losses has now risen from the $38 million figure initially cited by AnchorWatch CEO and co-founder Rob Hamilton, to roughly $88.6 million on Saturday, to more than $100 million on Monday.
Mentioned Coins
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.