The estimated damage from the Coldcard wallet security failure has nearly doubled following a detailed blockchain forensics investigation. According to reporting by Galaxy Research, the incident affected far more users than initially believed, with approximately $70.2 million in Bitcoin compromised across 1,196 addresses in a concentrated 41-minute attack window.
Galaxy Research, the analytical division of Galaxy Digital, traced the movement of 1,082.65 Bitcoin between 1:10 AM and 1:51 AM UTC on July 30 across blockchain blocks 960,183 to 960,191. The company identified the transactions about 30 hours before Coldcard—the hardware wallet manufacturer—released its initial security advisory, according to their analysis published Friday.
Attack Pattern Points to Coordinated Exploitation
The Galaxy analysis uncovered a distinct operational fingerprint that suggests the attack was not random but systematically executed. All identified transactions shared identical fee structures of 30 satoshis per virtual byte and contained no change outputs, a pattern that allowed researchers to connect seemingly disparate transactions to the same incident.
“The initial attack activity is identifiable on-chain through this pattern,” Galaxy Research noted, though they cautioned that subsequent attacks targeting Coldcard-generated addresses may employ different methods to evade detection.
This finding significantly expands upon earlier preliminary estimates. Rob Hamilton, CEO of security firm AnchorWatch, had initially calculated that 594.48 Bitcoin—valued around $38 million—moved across 500 transactions within a tighter three-block window. Galaxy’s broader investigation suggests Hamilton’s figure captured only part of the total impact.
Firmware Vulnerability Leaves Existing Seeds at Risk
Rodolfo Novak, co-founder of Coinkite, acknowledged the severity of the situation in a statement Friday, confirming that a firmware bug in Coldcard devices was responsible for the compromise. While Coinkite has released a hotfix that removes the software fallback path exploited in the attack, Novak emphasized that the update does not retroactively protect Bitcoin held in addresses generated using the vulnerable firmware versions.
The critical implication: users who created wallet seeds on affected Coldcard devices remain exposed. Novak recommended that all such users immediately transfer their holdings to addresses generated with non-vulnerable firmware or other secure methods.
Broader Questions About Cold Storage Security
The incident raises uncomfortable questions about hardware wallet security assumptions. Cold storage devices like Coldcard are marketed as air-gapped solutions resistant to online compromise, yet a firmware defect proved sufficient to compromise over $70 million in Bitcoin across more than a thousand accounts simultaneously.
The concentration of the attack within a 41-minute window and the uniform transaction fingerprint suggest that attackers either had advance knowledge of the vulnerability or discovered it through rigorous testing before execution. Neither scenario is comforting for the broader hardware wallet ecosystem.
The exact scope of affected users remains unclear, though Coinkite indicated it is still working to determine the full dimensions of the security failure. For Bitcoin holders relying on Coldcard devices, the situation underscores the ongoing tension between convenience and verifiable security—and the critical importance of firmware updates and operational diligence.