Galaxy Reports $70M Bitcoin Drained from 1,196 Coldcard Wallets Before Vulnerability Disclosure

iconCryptoBriefing
Share
AI summary iconSummary
Bitcoin news: Galaxy Research reported $70.2 million in Bitcoin was drained from 1,196 Coldcard Mk3 wallets in 41 minutes on July 30, 2026. The attack exploited a critical RNG vulnerability in firmware versions 4.0.1 to 5.0.3, allowing hackers to predict recovery seeds. Coinkite disclosed the vulnerability 30 hours later. Affected users were urged to generate new seeds and move funds. Stolen Bitcoin news shows funds were quickly consolidated, raising questions about who knew about the vulnerability news.

Hardware wallets are supposed to be the gold standard of crypto security. The whole pitch is simple: keep your private keys offline, away from hackers, away from exchanges, away from anything connected to the internet. For owners of certain Coldcard Mk3 devices, that pitch turned out to have a very expensive footnote.

On July 30, 2026, attackers drained 1,082.65 BTC, worth approximately $70.2 million, from 1,196 wallets in roughly 41 minutes, according to Galaxy Research. The exploit hit just 30 hours before Coinkite, the company behind Coldcard, publicly disclosed a critical vulnerability in the device’s firmware.

What went wrong, and why it matters

The flaw sits in the random number generator, or RNG, embedded in Coldcard Mk3 firmware versions 4.0.1 through 5.0.3.

Here is why that is a serious problem. When you set up a hardware wallet, the device generates a recovery seed, essentially a master password derived from a string of random numbers. If those numbers are not truly random, the seed becomes predictable. A predictable seed means an attacker who knows the pattern can calculate your private key without ever touching your device.

Advertisement

Block’s engineering team independently identified the root cause of the RNG flaw and published a detailed report on the same day Coinkite issued its security advisory. Both disclosures landed on July 30, 2026, the same day the wallets were already empty.

Coinkite was clear that the vulnerability did not affect every Coldcard device, only those running the specific compromised firmware versions. The company urged any affected users to generate entirely new recovery seeds immediately and move their funds.

How the attack unfolded

The efficiency of the drain is what stands out. Forty-one minutes to sweep 1,196 wallets across more than $70 million in Bitcoin is not a manual operation. This required automation, prior reconnaissance, and a pre-built list of vulnerable addresses.

On-chain data showed that the source wallets had been dormant for extended periods before the attack. That detail matters. It suggests the affected users were long-term holders, people who set up their Coldcard devices years ago and had not moved their funds since, likely because they trusted the hardware to keep everything safe.

Once the attack began, stolen funds were rapidly consolidated into fewer addresses. Galaxy’s research flagged that one specific address received approximately 594 BTC from the sweep.

The 30-hour window and what it implies

The timing here is the most uncomfortable part of this story. The wallets were drained roughly 30 hours before Coinkite’s public disclosure. That gap raises a question that the security community will be asking for some time: who knew about this vulnerability, and when?

It is possible the attacker independently discovered the RNG flaw and moved before either Coinkite or Block published their findings. Neither Coinkite nor Galaxy has alleged any wrongdoing in the disclosure process. Coinkite’s advisory made no claims about prior knowledge on the attacker’s part. The company focused its public communication on urging users to act immediately, generate new seeds, and verify which firmware version their device was running.

What this means for hardware wallet users

For anyone holding crypto on a hardware wallet, the immediate takeaway is straightforward. Firmware versions are not cosmetic updates. An RNG flaw is as close to a catastrophic vulnerability as exists in this space, because it undermines the very foundation of key generation. Users of any hardware wallet should know which firmware version they are running and verify that their device manufacturer has not issued any security advisories.

The speed and scale of the $70.2 million drain also signals something about attacker sophistication. Whoever executed this had the technical depth to exploit an RNG vulnerability, the infrastructure to automate sweeps across nearly 1,200 wallets simultaneously, and the operational discipline to move within a narrow window before public disclosure.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.