More than 1,000 bitcoin, worth roughly $70 million, was drained from 1,196 Coldcard hardware wallets in just 41 minutes on July 30, according to a detailed analysis by Galaxy Research reported by CoinDesk. The theft, which swept 1,082.65 BTC across six blocks, did not require physical access to the devices—only the ability to guess the private keys from weak seed generation.
The Firmware Flaw That Undermined Cold Storage
The attack exploited a critical flaw in certain Coldcard firmware versions that generated seed phrases with insufficient entropy, making them computationally enumerable. Galaxy Research found that an attacker could systematically recreate likely private keys offline and sweep funds without ever connecting to the targeted hardware. This is not the first time a Coldcard firmware issue has led to catastrophic losses; earlier a bug resulted in Coldcard Firmware Bug Drains 594 BTC in 25 Minutes, $38 Million Stolen.
Response and Wider Security Implications
Coinkite, the manufacturer, quickly reacted. As highlighted in our coverage, Coinkite CEO Tells Coldcard Users to ‘Move Your Funds Now’ Amid Security Alert, BOJ Keeps Rate. The ongoing risk remains high because owners cannot easily determine if their seeds were generated on vulnerable firmware, and more wallets may be at risk.
The incident underscores the critical importance of robust random-number generation in hardware wallets. Galaxy Research, beyond its forensic analysis, has also established a Galaxy Sets Up $5 Million Fund to Help Shield Bitcoin Against Quantum Computing Threats to address long-term cryptographic risks.