Community Trust ScoreVerified
Galaxy Research, the research arm of crypto investment firm Galaxy Digital, tracked down 1,196 Coldcard wallet addresses that bled out 1,082.65 Bitcoin — roughly $70.2 million gone — all within a 41-minute window. That’s a pretty significant jump from what anyone thought they were dealing with at the start.
The Bitcoin movements happened between 1:10 AM and 1:51 AM UTC on July 30, spread across blocks 960,183 through 960,191. What makes the timing especially striking: all of it played out about 30 hours before Coldcard even released its first security advisory. Users were sitting on compromised wallets and didn’t know it yet. AnchorWatch CEO Rob Hamilton had earlier pegged the damage at 594.48 Bitcoin — around $38 million — across 500 transactions in just three blocks. Galaxy’s research basically doubled that picture.
Not a small revision.
What the Transaction Pattern Showed
Galaxy Research’s analysis found some very specific fingerprints in the attack transactions. Uniform fees of 30 satoshis per virtual byte. No change outputs. Those two characteristics together paint a clean picture of the initial breach on-chain, and they’re the kind of details that let researchers trace what happened with some confidence.
But here’s the catch — Galaxy Research was clear that future attacks on Coldcard-generated addresses probably won’t look the same. Whoever pulled this off could simply change the fee structure or introduce change outputs next time, and the pattern-matching approach breaks down. That’s a real problem for anyone trying to build detection tools around what happened on July 30. The blockchain forensics community is basically on notice that the playbook can shift.
Coinkite co-founder Rodolfo Novak didn’t dodge responsibility. He acknowledged the firmware bug directly and said the company is taking ownership of the lapse. Coinkite pushed out a hotfix to cut off the software fallback path that made the exploit possible in the first place.
That’s the good news. The bad news is harder to fix.
Why the Hotfix Isn’t Enough for Everyone
Novak was blunt about this: the update doesn’t secure seeds that were already generated on the vulnerable firmware. If a user created a seed while running the compromised version, that seed is still at risk. The hotfix closes the door going forward — it doesn’t go back in time and clean up what’s already been created.
Coinkite’s guidance is straightforward. If you generated a seed on the affected firmware, move your funds to a new seed now. Don’t wait for more details. Don’t assume the hotfix covers you. It’s the kind of advisory that sounds simple but requires users to actually act, and in practice a lot of people won’t see it in time or won’t fully understand what it means for their specific setup.
Hardware wallets have long been considered the gold standard for self-custody in crypto. The pitch has always been that keeping your keys offline, on a dedicated device, is safer than anything a software wallet or exchange can offer. Incidents like this one complicate that story — not because hardware wallets are suddenly worthless, but because firmware vulnerabilities can still exist, and when they do the damage can be fast and large.
The $70.2 million figure is a reminder of how concentrated losses can get in a short burst. Forty-one minutes. Roughly 1,200 wallets. The speed of it is almost hard to process.
Investigation Still Open
Coinkite hasn’t finished its investigation. The full scope of the incident is still undetermined, and the company hasn’t released details on what additional protective measures might be coming or how many more users could be affected beyond the 1,196 addresses Galaxy Research identified. No further disclosure timeline has been given.
It’s unclear yet whether the 1,196 addresses represent the ceiling of affected wallets or just what’s visible on-chain so far. Galaxy Research’s methodology focused on the specific transaction characteristics from that 41-minute window, which means wallets drained before or after that window — or drained using a different fee structure — might not show up in the count.
Users who ran any version of Coldcard firmware during the relevant period should probably treat their existing seeds as suspect until Coinkite confirms otherwise. The company’s own advice points in that direction.
Coinkite says it’s continuing to investigate. No timeline on when more details drop.
Frequently Asked Questions
How much Bitcoin was lost in the Coldcard wallet incident?
Galaxy Research identified 1,082.65 Bitcoin lost across 1,196 wallet addresses, valued at approximately $70.2 million, all within a 41-minute window on July 30.
Does the Coinkite hotfix protect existing wallet seeds?
No — Coinkite co-founder Rodolfo Novak said the hotfix removes the vulnerable software fallback path but does not secure seeds already generated on the compromised firmware; users are advised to move funds to a new seed.





