Galaxy Research Traces $70M Coldcard Bitcoin Wallet Attack to 1,196 Drained Addresses

iconCryptofrontnews
Share
AI summary iconSummary
Bitcoin breaking news: Galaxy Research traced a $70.2 million Bitcoin heist to 1,196 drained addresses on July 30. The attack, lasting 41 minutes, moved 1,082.65 BTC across six blocks. Transactions showed no change outputs and fixed fees, pointing to an automated operator. Coinkite confirmed a Coldcard firmware flaw and issued emergency updates. Bitcoin news outlets are closely following the incident.
  • Galaxy traced 1,082.65 BTC stolen from 1,196 Coldcard-linked addresses.
  • Fixed transaction patterns linked the 41-minute attack to one operator.
  • Coinkite issued emergency firmware updates after confirming the flaw.

Galaxy Research said it identified 1,196 Bitcoin addresses drained of 1,082.65 BTC, worth about $70.2 million, during a 41-minute period on July 30. According to Galaxy Research, the transactions occurred between 01:10:20 UTC and 01:51:26 UTC across six Bitcoin blocks before Coinkite publicly disclosed a firmware vulnerability affecting certain Coldcard hardware wallets. The firm also said it found no additional matching transactions over the past 30 days.

Onchain Pattern Linked The Transactions

According to Galaxy Research, every transaction paid the same 30.0 sat/vB network fee and created no change output. Researchers said that fixed fee distinguished the activity from normal Bitcoin consolidations and pointed to a single automated operator.

The report stated that 1,183 native SegWit addresses, seven BIP-49 addresses and six BIP-44 addresses were drained. Galaxy Research said that distribution matched automated scanning across multiple wallet derivation paths.

Researchers also found that the transactions appeared in batches rather than continuously. Three intervening blocks contained no sweep activity during the 41-minute period. Meanwhile, Galaxy Research said four Bitcoin addresses received the stolen funds. It added that those holdings have not moved since the initial consolidation.

Firmware Bug Prompted Emergency Response

Coinkite first warned users of an issue affecting seeds generated on Coldcard Mk3 devices running firmware version 4.0.1 and later. The company later expanded the advisory to include certain Mk4, Mk5 and Coldcard Q firmware versions while releasing emergency firmware updates.

EliteFXLabs Banner

Coinkite CEO Rodolfo Novak accepted responsibility for the firmware bug and apologized to users. He also said the company’s review process failed to detect the issue before release.

Novak further suggested artificial intelligence may have helped uncover the vulnerability. He said AI-assisted code review can identify software weaknesses faster than traditional manual reviews.

Researchers Warn More Attacks Remain Possible

Galaxy Research said future attacks remain possible if users keep funds in affected single-signature Coldcard addresses. However, the firm stressed that future incidents may not follow the same onchain transaction pattern.

According to Galaxy Research, the identifiable pattern only links the initial attacker. It does not detect future thefts because those transactions could appear identical to legitimate wallet transfers.

The firm urged users to move funds into trusted custodial services or multisignature self-custody setups. Coinkite also advised users to install updated firmware, generate a new seed, test the wallet with a small transfer, and retain old backups until migration finishes.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.