Galaxy Research Raises Coldcard Bitcoin Loss Estimate to $70.2M

iconNS3
Share
AI summary iconSummary
Bitcoin news: Galaxy Research now estimates the Coldcard wallet incident involved $70.2 million in losses, based on 1,082.65 Bitcoin sent from 1,196 addresses. The transactions took place between 1:10 AM and 1:51 AM UTC on July 30. All used 30 satoshis per virtual byte fees and no change outputs. Coinkite’s Rodolfo Novak said a hotfix removed the vulnerable software path but doesn’t protect old seeds. Affected users may need to rotate seeds due to the risk. Traders monitoring altcoins to watch should also track Bitcoin news for broader market reactions.

Key Point

Galaxy Research identified 1,196 addresses linked to the Coldcard wallet incident that lost 1,082.65 Bitcoin, worth about $70.2 million at the time of the transactions. Galaxy Research traced the Bitcoin movements between 1:10 AM and 1:51 AM UTC on July 30 across blocks 960,183 to 960,191. AnchorWatch CEO and co-founder Rob Hamilton had earlier estimated that 594.48 Bitcoin moved across 500 transactions within a three-block window. Galaxy Research said the transactions shared identical 30 satoshis per virtual byte fees and no change outputs. Coinkite co-founder Rodolfo Novak said Coinkite released a hotfix to remove the software fallback path, but the update does not protect seeds generated on vulnerable firmware.

Why it matters: A firmware bug may force affected users to rotate seeds because wallet security depends on safe seed generation.

Market Sentiment

Bearish, Stress-on, Tech-driven, Fear.

Reason: The higher Coldcard loss estimate points to direct self-custody security risk.

Similar Past Cases

In June 2023, Atomic Wallet users lost more than $35 million in a wallet compromise, which showed how wallet-level failures can create large user losses without an exchange failure. (Fortune) Difference: Atomic Wallet was a software wallet case, while the Coldcard incident is framed as a firmware bug affecting generated seeds.

Ripple Effect

The main channel is trust in self-custody hardware and seed-generation workflows. If similar on-chain fingerprints appear from other generated addresses, then confidence pressure could widen across wallet providers. If future attacks avoid the same fingerprint, then detection may become harder.

Opportunities & Risks

Opportunities: If Coinkite defines the full scope of vulnerable firmware, then waiting for scope clarity before adding funds to Coldcard-generated addresses limits operational risk. When users generated seeds on vulnerable firmware, then moving funds to a new seed is the primary risk-reduction step identified by Novak.

Risks: If future attacks do not follow the same on-chain fingerprint, then relying on the identified fee and change-output pattern may miss exposure. Reducing reliance on unchanged vulnerable seeds limits downside if the firmware issue proves broader than current tracing shows.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.