XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Markets
● Markets

Coldcard Firmware Bug Linked to $70M Bitcoin Drainage, Galaxy Research Analysis Shows

Galaxy Research identified 1,196 addresses that lost over $70 million in Bitcoin during a 41-minute window, revealing the broader scope of a critical Coldcard wallet security incident stemming from a firmware vulnerability.

JM
by Jacob Marquez · Markets Desk
Published August 1, 2026 · 3 min read

Massive Coordinated Bitcoin Loss Traced to Firmware Flaw

A critical security vulnerability affecting Coldcard wallet users resulted in the loss of approximately $70.2 million in Bitcoin, according to analysis by Galaxy Research, the research division of Galaxy Digital. The incident centered on 1,196 addresses that collectively lost 1,082.65 Bitcoin between 1:10 AM and 1:51 AM UTC on July 30, spanning a compressed 41-minute timeframe across blockchain blocks 960,183 to 960,191.

The attack’s coordinated nature became apparent through identifiable on-chain patterns, according to Galaxy Research. The transactions shared distinctive characteristics including identical 30 satoshi-per-virtual-byte fees and an absence of change outputs—hallmarks that allowed researchers to trace the incident’s scope. However, Galaxy Research cautioned that subsequent attacks targeting Coldcard-generated addresses may employ different methodologies, potentially complicating detection efforts.

Expanding Estimates and Coinkite’s Response

Earlier preliminary investigation by AnchorWatch CEO Rob Hamilton had identified a smaller subset of the attack, estimating 594.48 Bitcoin worth approximately $38 million had moved across 500 transactions within just three blockchain blocks. Galaxy Research’s broader analysis more than doubled the incident’s scope, revealing the true scale of the compromise occurred roughly 30 hours before Coldcard issued its initial security advisory.

Coinkite, the company behind Coldcard, acknowledged responsibility for the underlying firmware bug through a statement by co-founder Rodolfo Novak. The company released a hotfix designed to eliminate a problematic software fallback path that enabled the attack. However, Novak emphasized a critical limitation: the update cannot retroactively protect Bitcoin or other assets associated with seed phrases that were generated using the vulnerable firmware. Coinkite advised all users who generated seeds on affected firmware versions to immediately transfer their assets to wallets created with non-vulnerable firmware versions.

Security Implications for Hardware Wallet Users

The incident underscores vulnerabilities inherent in hardware wallet implementations, where firmware-level defects can compromise large numbers of addresses simultaneously. The ability to identify and trace the attack’s patterns highlights both the transparency of blockchain analysis and the lasting consequences of cryptographic compromises—once a seed is generated using vulnerable code, the security breach cannot be undone through patches alone.

The Coldcard incident joins a growing list of major security events affecting major cryptocurrency infrastructure, following recent incidents including the $2.6 million ADA theft linked to wallet vulnerabilities. These developments reinforce the critical importance of wallet security hygiene and the necessity for users to remain vigilant regarding firmware updates across all cryptocurrency holdings.

Source: Galaxy Research, via Cointelegraph. Not financial advice.

Why it matters: Hardware wallet compromises of this scale demonstrate that no cryptocurrency storage solution is immune to risk, reinforcing the importance of diversified security practices across the entire digital asset ecosystem.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Markets Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.