Bitcoin losses linked to Coldcard vulnerability grow to $70 million, Galaxy Research says

摘要:Galaxy Research reported that nearly 1,200 addresses were drained of more than 1,000 BTC, worth about $70 million, in an attack tied to a vulnerability in Coldcard hardware wallets. The issue affected seeds generated on Coldcard Mk3 devices running firmware version 4.0.1 or later, with the advisory later expanded to include certain Mk4, Mk5, and Coldcard Q firmware versions. Coinkite released emergency firmware updates, and CEO Rodolfo Novak apologized, accepting full accountability and suggesting AI-assisted code review may have exposed the bug. Galaxy noted the pattern indicated a single attacker but that future attacks remain possible on any Coldcard-generated address. Users are urged to update firmware, generate a new seed, test a small transaction, and retain old backups until funds are moved.

Quick Take

  • The firm said nearly 1,200 addresses were drained of more than 1,000 BTC, worth about $70 million in transactions it linked to a vulnerability affecting Coldcard hardware wallets.

Galaxy Research said Friday that nearly 1,200 addresses were drained of more than 1,000 BTC, worth about $70 million in transactions it linked to a vulnerability affecting Coldcard hardware wallets.

On Thursday, Coinkite advised that there was an ongoing issue affecting seeds generated on Coldcard Mk3 devices. “Out of an abundance of caution, Coinkite is warning all users who generated a seed using a Mk3 on version 4.0.1 (March 2021) or any subsequent version that their funds may be at risk,” the crypto hardware maker said.

Coinkite later expanded the advisory to include certain Mk4, Mk5 and Coldcard Q firmware versions, and released emergency firmware updates for all affected models.

Coinkite CEO Rodolfo Novak, known as NVK, apologized Friday and said the company took “full accountability for the firmware bug,” acknowledging that its review process had failed to catch it.

Novak also suggested the vulnerability may have been uncovered using artificial intelligence, calling the incident “a sober reality of the new AI paradigm.” He warned that AI-assisted code review can identify latent bugs faster than even experienced security experts, allowing attackers to exploit weaknesses in publicly available code.

Galaxy Research then published its findings on social media.

“We mapped the flow of funds for the Coldcard vulnerability based on the pattern identified by engineers at Block and shared by [Clay Garrett]: 1,196 addresses drained in full for 1,082.65 BTC (~$70.2M) between 01:10:20 and 01:51:26 UTC July 30.”

Coinkite's advisory followed multiple online reports of bitcoin being drained from users' Coldcard wallets.

“The nature of the vulnerability means that future attacks are possible on any Coldcard-generated address and those do not need to match this pattern,” Galaxy Research also said Friday. “The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins.”

Coinkite has said users should update their firmware and generate a new seed. They should also test the new wallet with a small transaction before transferring all of their funds and keep the old backup until the transaction is complete.

Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

免責聲明

本文觀點僅代表作者個人觀點,不構成本平台的投資建議,本平台不對文章信息準確性、完整性和及時性作出任何保證,亦不對因使用或信賴文章信息引發的任何損失承擔責任
上一篇

劍橋大學研究顯示以太坊(ETH)位居PoS能耗強度下游

下一篇

Merck與Hashgraph Group推出基於Hedera的產品護照以符合歐盟合規要求