Galaxy Research identifies 1,367 BTC drained in attacks on Coldcard addresses

1 hour ago 11

Hardware wallets are supposed to be the vault, not the vulnerability. But a newly uncovered firmware defect in Coldcard Mk3 devices has flipped that assumption, with Galaxy Research confirming that 1,367.05 BTC, worth roughly $88.6M, was drained across three coordinated attack waves targeting 4,585 affected addresses.

The scale of the theft is jarring. Earlier estimates had pegged losses at around 594 BTC from approximately 500 addresses. Galaxy’s on-chain analysis more than doubled that figure, revealing a much broader and more methodical assault than initially understood.

What happened, and how fast

The largest single wave hit on July 30, 2026, and it was efficient in the worst possible way. Attackers swept 1,082.65 BTC, roughly $70.2M, in just 41 minutes.

Galaxy’s analysis found that the first two waves shared nearly identical transaction fingerprints, specifically hardcoded fees of 30 sat/vB and the same batching patterns. That level of consistency suggests a single operator, or at minimum a single toolkit. The third wave broke from that pattern, pointing to either a different actor or a deliberate tactical shift.

The stolen funds have largely stayed put. The BTC has not been significantly moved since the thefts, sitting in a small number of attacker-controlled addresses.

The root cause: predictable randomness

The flaw in Coldcard Mk3 firmware, present in versions 4.0.1 and later, introduced in March 2021, caused the device’s random number generator to produce weak, predictable outputs. The seeds it created were not actually random, which meant an attacker with enough computing power could enumerate possible seeds offline and match them to real addresses on the blockchain, sweeping funds from single-signature addresses without ever needing physical access to the device.

Block’s engineering team is credited with first surfacing the RNG issue publicly. Coinkite, the company behind Coldcard, issued an advisory approximately 30 hours after the initial sweeps began.

Coldcard Mk4, Q, and Mk5 devices do not appear to be affected by the same flaw. Users holding funds on compromised Mk3 wallets are being urged to generate entirely new seeds on those newer models rather than simply transferring balances within the same hardware generation.

What this means for hardware wallet security and investors

The fee behavior in the attacks is also worth noting. The hardcoded 30 sat/vB rate used in the first two waves was between 30 and 75 times the median fee at the time, according to Galaxy’s findings. Attackers were clearly willing to pay a premium to ensure rapid confirmation.

For active Bitcoin holders, the immediate question is exposure. Anyone using a Coldcard Mk3 device running firmware from version 4.0.1 onward should treat their current seed as potentially compromised and migrate funds to a freshly generated wallet on unaffected hardware. Checking firmware version history and cross-referencing with Coinkite’s advisory is the first practical step.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article