Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
Galaxy Research identifies 1,367 BTC drained in attacks on Coldcard addresses

Galaxy Research identifies 1,367 BTC drained in attacks on Coldcard addresses

CryptobriefingCryptobriefing2026/08/02 07:21
By:Cryptobriefing

Hardware wallets are supposed to be the vault, not the vulnerability. But a newly uncovered firmware defect in Coldcard Mk3 devices has flipped that assumption, with Galaxy Research confirming that 1,367.05 BTC, worth roughly $88.6M, was drained across three coordinated attack waves targeting 4,585 affected addresses.

The scale of the theft is jarring. Earlier estimates had pegged losses at around 594 BTC from approximately 500 addresses. Galaxy’s on-chain analysis more than doubled that figure, revealing a much broader and more methodical assault than initially understood.

What happened, and how fast

The largest single wave hit on July 30, 2026, and it was efficient in the worst possible way. Attackers swept 1,082.65 BTC, roughly $70.2M, in just 41 minutes.

Advertisement
window.sevioads = window.sevioads || []; var sevioads_preferences = []; sevioads_preferences[0] = {}; sevioads_preferences[0].zone = "de1434f5-fa9e-44a6-93c3-4c2439763717"; sevioads_preferences[0].adType = "banner"; sevioads_preferences[0].inventoryId = "c5700508-581b-472c-8fdd-a931cdbfc8e1"; sevioads_preferences[0].accountId = "1e47efc1-ec2d-4fca-a8b9-354e249e5095"; sevioads.push(sevioads_preferences);

Galaxy’s analysis found that the first two waves shared nearly identical transaction fingerprints, specifically hardcoded fees of 30 sat/vB and the same batching patterns. That level of consistency suggests a single operator, or at minimum a single toolkit. The third wave broke from that pattern, pointing to either a different actor or a deliberate tactical shift.

The stolen funds have largely stayed put. The BTC has not been significantly moved since the thefts, sitting in a small number of attacker-controlled addresses.

The root cause: predictable randomness

The flaw in Coldcard Mk3 firmware, present in versions 4.0.1 and later, introduced in March 2021, caused the device’s random number generator to produce weak, predictable outputs. The seeds it created were not actually random, which meant an attacker with enough computing power could enumerate possible seeds offline and match them to real addresses on the blockchain, sweeping funds from single-signature addresses without ever needing physical access to the device.

Block’s engineering team is credited with first surfacing the RNG issue publicly. Coinkite, the company behind Coldcard, issued an advisory approximately 30 hours after the initial sweeps began.

Coldcard Mk4, Q, and Mk5 devices do not appear to be affected by the same flaw. Users holding funds on compromised Mk3 wallets are being urged to generate entirely new seeds on those newer models rather than simply transferring balances within the same hardware generation.

What this means for hardware wallet security and investors

The fee behavior in the attacks is also worth noting. The hardcoded 30 sat/vB rate used in the first two waves was between 30 and 75 times the median fee at the time, according to Galaxy’s findings. Attackers were clearly willing to pay a premium to ensure rapid confirmation.

For active Bitcoin holders, the immediate question is exposure. Anyone using a Coldcard Mk3 device running firmware from version 4.0.1 onward should treat their current seed as potentially compromised and migrate funds to a freshly generated wallet on unaffected hardware. Checking firmware version history and cross-referencing with Coinkite’s advisory is the first practical step.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

U.S. stocks opened higher and fluctuated, the Japanese yen rebounded more than 1% intraday, 10-year U.S. Treasury yields broke above 5.22% again, and U.S. crude oil once fell nearly 3%.

After the release of U.S. consumer confidence data, the S&P and Nasdaq turned negative, while the Dow is poised to break a three-day losing streak but is set for a fourth consecutive weekly decline. Meta pulled back, falling more than 3% during the session. The U.S. 10-year Treasury yield surpassed 5.22% again, marking a new high for the third day in a row since 2007, while the 30-year yield reached its highest level since 2004. The yen/dollar pair surged 1.2% intraday, as Japanese and U.S. officials successively signaled concerns over the weak yen. Expectations for a diplomatic resolution between the U.S. and Iran are rising, halting crude oil's two-day climb.

华尔街见闻•2026/09/25 16:36

US Treasury volatility surges, triggering alarms! BofA’s Hartnett warns of rising deleveraging risks as higher yields become main threat to the market

Bank of America strategist Michael Hartnett warns that the recent sharp rise in volatility in the US bond market is increasing the risk of broader deleveraging in financial markets.

智通财经•2026/09/25 15:36

U.S. diesel prices surge 83% this year! Apollo Chief Economist warns: Cost pass-through may make core inflation more stubborn, Federal Reserve can't ignore it

Torsten Slok, Chief Economist at Apollo Global Management, has warned that the inflation threat posed by the surge in U.S. diesel prices to historic highs may be more serious than the Federal Reserve currently realizes.

智通财经•2026/09/25 15:16