Bitcoin losses linked to Coldcard vulnerability grow to $70 million, Galaxy Research says

Quick Take

  • The firm said nearly 1,200 addresses were drained of more than 1,000 BTC, worth about $70 million in transactions it linked to a vulnerability affecting Coldcard hardware wallets.
Advertisement

Galaxy Research said Friday that nearly 1,200 addresses were drained of more than 1,000 BTC, worth about $70 million in transactions it linked to a vulnerability affecting Coldcard hardware wallets.

On Thursday, Coinkite advised that there was an ongoing issue affecting seeds generated on Coldcard Mk3 devices. "Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk," the crypto hardware maker said.

Coinkite later expanded the advisory to include certain Mk4, Mk5 and Coldcard Q firmware versions, and released emergency firmware updates for all affected models.

Coinkite CEO Rodolfo Novak, known as NVK, apologized Friday and said the company took "full accountability for the firmware bug," acknowledging that its review process had failed to catch it.

Novak also suggested the vulnerability may have been uncovered using artificial intelligence, calling the incident "a sober reality of the new AI paradigm." He warned that AI-assisted code review can identify latent bugs faster than even experienced security experts, allowing attackers to exploit weaknesses in publicly available code.

Galaxy Research then published its findings on social media.

"We mapped the flow of funds for the Coldcard vulnerability based on the pattern identified by engineers at Block and shared by [Clay Garrett]: 1,196 addresses drained in full for 1,082.65 BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC July 30."

Coinkite's advisory followed multiple online reports of bitcoin being drained from users' Coldcard wallets.

"The nature of the vulnerability means that future attacks are possible on any Coldcard-generated address and those do not need to match this pattern," Galaxy Research also said Friday. "The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins."

Coinkite has said users should update their firmware and generate a new seed. They should also test the new wallet with a small transaction before transferring all of their funds and keep the old backup until the transaction is complete.


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.