Loading prices…
🩸BEARISH

Coldcard firmware flaw drained $70M in BTC from 1,196 wallets

Galaxy mapped the July 30 sweep to 1,196 wallets and 1,082 BTC drained in 41 minutes via a seed-generation bug that collapsed the keyspace to a few billion options.

Coldcard firmware flaw drained $70M in BTC from 1,196 wallets
Coldcard firmware flaw drained $70M in BTC from 1,196 wallets
Coldcard firmware flaw drained $70M in BTC from 1,196 wallets
Coldcard firmware flaw drained $70M in BTC from 1,196 wallets

More than 1,000 BTC, worth roughly $70 million, were drained from 1,196 Coldcard wallets in a 41-minute window on July 30, nearly double the loss first reported. Galaxy Research mapped the full event on Friday, tracing 1,082.65 BTC swept across six blocks between 01:10 and 01:51 UTC, with three intervening blocks empty, which pointed to batched broadcasts rather than continuous sweeping. The proceeds sit in four addresses and have not moved, and early reporting captured only one of those addresses, which is why the headline figure has kept climbing.

Why it matters

The exploit did not require touching the device. A firmware flaw in certain Coldcard models told the wallet to skip its dedicated hardware randomness generator and fall back to a basic software substitute seeded from the chip's serial number and clock registers. The serial number is fixed factory metadata, and the clock values are timing state an attacker can narrow down or measure on a device of their own. The range of keys the device could ever produce collapsed from astronomically vast to enumerable: roughly four billion possibilities on the Mk4, Q, and Mk5, and fully recoverable on the older Mk2 and Mk3. An attacker generates candidate seeds offline, derives each candidate's addresses, and checks them against the public blockchain, all without the victim device ever being online.

Market impact

Galaxy warned further waves are likely if owners do not move their funds, and there is no reliable test a user can run to determine whether their seed sits inside the reproducible range. Coinkite has warned Mk3 owners and says its newer devices are unaffected, while Block's report places the Mk2, Mk4, Q, and Mk5 in scope as well. The attacker did leave a trail: Block's Clay Garrett said on X that the operator used a paid account at a well-known blockchain data provider to query source addresses during the sweeps, and the provider's internal logs matched the workflow with what he called extraordinary specificity. Block has passed the information to authorities, and the proceeds remain unmoved across four addresses, leaving investigators a window to act before the next sweep begins.

Related tokens
$BTC

Frequently asked questions

  1. How did attackers drain Coldcard wallets without touching them?

    A firmware flaw told the device to skip its hardware randomness generator and fall back to a software substitute seeded from the chip's serial number and clock registers, collapsing the keyspace to a few billion options. Attackers enumerated candidate seeds offline and checked derived addresses against the public…

  2. How much bitcoin was stolen and from how many wallets?

    Galaxy Research traced 1,082.65 BTC drained from 1,196 Coldcard wallets across six blocks between 01:10 and 01:51 UTC on July 30, totaling roughly $70 million and sitting unmoved across four addresses.

  3. Which Coldcard models are affected by the flaw?

    Coinkite has warned Mk3 owners and says newer devices are unaffected, while Block's report places the Mk2, Mk4, Q, and Mk5 in scope as well. The keyspace on the Mk4, Q, and Mk5 is narrowed to roughly four billion possibilities, and is fully recoverable on the Mk2 and Mk3.

  4. Can Coldcard owners check whether their wallets are exposed?

    No. Galaxy warned there is no test a user can run against their own wallet to determine whether their seed sits inside the reproducible range, so anyone who generated a seed on the affected firmware has to assume the worst until they move funds.

  5. What leads do investigators have on the attacker?

    Block's Clay Garrett said the operator used a paid account at a well-known blockchain data provider to query source addresses during the sweeps, and the provider's internal logs matched the workflow with what he called extraordinary specificity. Block has passed the information to authorities.

Source attribution
Aggregated from CoinDesk · Verified · Last refreshed 1h ago
Open original →