Coldcard-Linked Bitcoin Losses Reach $70M Amid Firmware Vulnerability

iconNS3
Share
AI summary iconSummary
Bitcoin news: Galaxy Research reported $70.2 million in losses from 1,196 addresses on July 30, linked to a Coldcard firmware vulnerability. Block engineers identified the flaw, which Coinkite warned affects Coldcard Mk3, Mk4, Mk5, and Coldcard Q devices. The firm issued emergency firmware updates. Vulnerability news highlights the risks for users on affected versions. Coinkite apologized for the bug and urged immediate action.

Key Point

Galaxy Research said 1,196 addresses were drained in full for 1,082.65 BTC, or about $70.2 million, between 01:10:20 and 01:51:26 UTC July 30. Galaxy Research linked the flows to a Coldcard vulnerability based on a pattern identified by engineers at Block and shared by Clay Garrett. Coinkite first warned users who generated seeds on Coldcard Mk3 devices using version 4.0.1 or later that their funds may be at risk. Coinkite later expanded the advisory to certain Mk4, Mk5 and Coldcard Q firmware versions and released emergency firmware updates. Coinkite CEO Rodolfo Novak, known as NVK, apologized Friday and said the company took full accountability for the firmware bug.

Why it matters: Seed-generation weaknesses can turn a device-level firmware bug into direct custody risk for users who hold funds on affected wallets.

Market Sentiment

Bearish, Stress-on, Event-driven, De-risking.

Reason: Galaxy Research linked more than 1,000 BTC in drained funds to a Coldcard vulnerability, so traders may read the event as direct custody risk.

Similar Past Cases

In 2022, Solana developers traced a wallet drain to Slope mobile wallets, and almost 8,000 wallets had been affected as of 5 a.m. UTC. Slope recommended users create a new seed phrase wallet and transfer assets to the new wallet. (The Block) The difference is that the Slope case involved mobile software wallets, while the current event involves Coldcard hardware wallet firmware and Bitcoin seeds.

Ripple Effect

Custody confidence can weaken if users view seed generation as unreliable across affected devices. If new drains appear from affected seed cohorts, then users may move funds from self-custody into alternative custody setups while wallets are rotated. If emergency updates stop further drains, then the impact may remain contained to users with affected seeds.

Opportunities & Risks

Opportunities: When Coinkite's emergency firmware updates and new-seed process stop new drains, then staged transfers after a small test transaction can be a safer recovery signal.

Risks: If future attacks appear on Coldcard-generated addresses, then treating old seeds as compromised reduces exposure to further custody losses.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.