An attacker drained 1,082.65 Bitcoin, worth about $70 million, from 1,196 wallets during a 41-minute sweep on July 30. Galaxy Research mapped the full event after early reports captured only part of the theft.
Galaxy found that the attacker moved the bitcoin between 01:10 and 01:51 UTC across six blocks. Three blocks between those transfers contained no related transactions. That pattern indicates the operator broadcasts transactions in batches rather than sending them continuously. The stolen bitcoin now sits in four addresses and has not moved.
Early coverage tracked only one destination address, which kept the first loss estimate much lower. Galaxy later connected the remaining addresses and nearly doubled the reported amount. The attacker drained 1,183 native SegWit wallets, seven older standard addresses, and six still older addresses. This mix points to systematic seed testing across several derivation paths.
Coldcard devices should create seeds with a dedicated hardware random number generator. An internal build setting instead told affected firmware to skip that generator. A supporting library checked whether the setting existed but failed to check whether developers had enabled it. The software then used a fallback tied to the chip serial number and clock registers.
The serial number remains fixed, while an attacker can narrow or reproduce clock timing. As a result, the possible seeds fell from an immense range to a searchable set. Security teams reproduced key generation on older Mk2 and Mk3 devices. For the Mk4, Q, and Mk5, they estimated a range of about four billion possible seeds.
An attacker can generate candidate seeds, derive their addresses, and compare them with the public blockchain. The victim’s hardware never needs to connect during that search. What protects cold storage when an attacker can recreate the seed without touching the wallet?
Also Read: Bitcoin Falls While Apple Faces $1.8M Sparrow Wallet Lawsuit
Galaxy warned that more sweeps could follow unless affected owners move their funds. Owners cannot run a test that shows whether their seed falls inside the reproducible range. Coinkite, Coldcard’s maker, warned Mk3 owners and said newer models remain unaffected. Block’s report also placed the Mk2, Mk4, Q, and Mk5 within the affected scope.
The disagreement leaves users without a verified way to separate safe devices from exposed ones. Anyone who generated a seed with affected firmware must treat that seed as vulnerable. Block’s Clay Garrett said the operator used a paid account at a well-known blockchain data provider. Internal logs reportedly matched the suspected queries by number, timing, and sequence.
The provider supplied standard services and saw no clear sign of the attacker’s purpose. Block passed the account information and related evidence to authorities. Anthropic separately reported that one of its models weakened a candidate post-quantum algorithm within 60 hours. Researchers had reviewed that design for two years before the model’s test.
Galaxy Research traced the theft to 1,196 wallets and four holding addresses. The seed-generation flaw reduced key security to a searchable range, while reports disagree on affected models. Galaxy warned that further sweeps could follow, making fund movement the only action described for potentially exposed owners.
Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp
_____________
Disclaimer: Analytics Insight does not provide financial advice or guidance on cryptocurrencies and stocks. Also note that the cryptocurrencies mentioned/listed on the website could potentially be risky, i.e. designed to induce you to invest financial resources that may be lost forever and not be recoverable once investments are made. This article is provided for informational purposes and does not constitute investment advice. You are responsible for conducting your own research (DYOR) before making any investments. Read more about the financial risks involved here.