Coldcard Bitcoin Losses Hit $70M in Galaxy Analysis

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Galaxy Research identified 1,196 addresses that lost 1,082.65 Bitcoin (~$70.2 million) between 1:10 AM and 1:51 AM UTC on July 30, expanding the scope of the Coldcard wallet exploit.
- The traced transactions occurred across blocks 960,183 to 960,191 — roughly 30 hours before Coldcard published its first security advisory, per an X post on Friday.
- Earlier analysis from AnchorWatch CEO Rob Hamilton had estimated 594.48 Bitcoin (~$38 million) across 500 transactions in a three-block window; the new figure is nearly double that.
- Galaxy Research said the attack transactions share a pattern — identical 30 satoshis per virtual byte fees and no change outputs — but warned future attacks on Coldcard-generated addresses may not follow the same fingerprint.
- Coinkite co-founder Rodolfo Novak accepted responsibility for the firmware bug in an X post Friday and said a hotfix has been released to remove the software fallback path.
- Novak warned the hotfix does not protect seeds already generated on vulnerable firmware and advised those users to move funds to a new seed.
Why it matters: Coldcard users who generated seeds on vulnerable firmware have no automatic remediation — they must manually migrate funds to a new seed. The 30-hour gap between the attack window and the first advisory means any remaining at-risk wallets sat exposed while users waited for official guidance.




