Saturday, 01 August 2026 · World
USD/EUR 0.8687 USD/GBP 0.7433 USD/JPY 158.5 USD/CNY 6.765 All rates →
RSS
EUROS The World Financial Report
Nº 21 Saturday, 01 August 2026 · World Edition
LATEST
Crypto

Coldcard Bitcoin Losses Double to $70M in Galaxy Analysis

EUROS Newsroom · 1h ago · 1 min read
Coldcard Bitcoin Losses Double to $70M in Galaxy Analysis

A deeper blockchain review has doubled the estimated losses from a Coldcard wallet firmware bug to $70.2 million, forcing the hardware maker to warn users that a recent software patch cannot salvage funds tied to compromised seeds.

The financial toll from the Coldcard wallet exploit is significantly worse than initially feared. Galaxy Research has traced 1,082.65 Bitcoin—worth roughly $70.2 million at the time of transfer—to 1,196 addresses drained during a 41-minute window on July 30.

This figure effectively doubles the preliminary damage assessment. AnchorWatch CEO and co-founder Rob Hamilton had previously calculated that 594.48 Bitcoin, valued at about $38 million, moved across 500 transactions in a much shorter, three-block span.

Galaxy Digital’s research arm pinned the heightened attack activity to between 1:10 AM and 1:51 AM UTC, spanning blocks 960,183 to 960,191. This aggressive extraction occurred approximately 30 hours before Coldcard’s parent company, Coinkite, issued its initial security advisory to the public.

Investigators identified the malicious transfers by a distinct on-chain fingerprint. The drained addresses shared identical transaction fees of 30 satoshis per virtual byte and entirely lacked change outputs. However, Galaxy cautioned that future exploits targeting Coldcard addresses may abandon this recognizable pattern.

The revelation that a hardware wallet can suffer a firmware-level compromise which permanently taints generated seeds is a critical development for institutional custody. For asset managers, the incident underscores that physical possession of a device does not guarantee asset safety if the initial key generation is flawed.

Coinkite co-founder Rodolfo Novak acknowledged the firm's liability for the vulnerability. In a statement on Friday, Novak said the company "takes responsibility for the firmware bug" and is actively working to determine the full extent of the compromise.

The firm has deployed a hotfix to eliminate the vulnerable software fallback path. Yet, for investors relying on self-custody, the mitigation comes with a severe limitation. Novak warned that the update "does not protect seeds generated on vulnerable firmware."

He strongly advised any user who created a seed on the flawed software to immediately sweep their remaining assets to a newly generated seed. Failure to migrate funds leaves any untouched Bitcoin on compromised addresses at ongoing risk of theft.