Galaxy Research linked a Coldcard firmware flaw to the theft of 1,082.65 BTC, worth about $70 million, from 1,196 addresses on July 30. Researchers said the coordinated withdrawals occurred within 41 minutes, making the case one of this year’s largest reported hardware wallet incidents.
Galaxy found a consistent transaction pattern across the stolen funds. The firm said the pattern pointed to one coordinated attacker behind the observed attack sequence. Still, the recorded transfers may not include every exposed wallet. Researchers warned that other vulnerable addresses could remain inactive or could move funds later.
Blockchain records cannot distinguish theft from a legitimate owner transfer when both use valid private keys. How many exposed wallets may still hold funds?
Coinkite first warned owners of Coldcard Mk3 devices running firmware version 4.0.1, released in March 2021. The company said seeds created with affected software could expose user funds. It later widened the advisory to selected firmware versions on Coldcard Mk4, Mk5, and Coldcard Q devices. Coinkite then issued emergency updates for every impacted model.
Chief Executive Rodolfo Novak, known as NVK, accepted responsibility and apologized to customers. He said the company’s internal review process failed to catch the defect before release.
Also Read: Bitcoin Security Faces New Questions After the Coldcard Wallet Hack
Novak said attackers may have found the flaw through artificial intelligence-assisted code analysis. He said such tools can detect subtle weaknesses faster than traditional manual reviews. That speed creates a growing challenge for software developers. The same technology can help defenders inspect code, yet it can also shorten the path from public release to exploitation.
Coinkite told affected users to install the latest firmware, create new wallet seeds, and move Bitcoin into new wallets. It also advised testing small transfers before moving larger balances.
The company told users to keep their original backups until every transfer succeeds. Coldcard wallets store private keys offline, but firmware bugs, supply chain risks, and configuration errors can still create attack paths.
Galaxy Research linked the July 30 theft of 1,082.65 BTC to vulnerable Coldcard wallet seeds across affected firmware versions. Coinkite released emergency updates and told users to create fresh seeds, test new wallets, and transfer funds while keeping original backups until every move succeeds.