BlocktoBlockto
Coldcard Wallet Losses Climb to $70 Million as More Addresses Confirmed Drained
BITCOIN NEWS

Photo: Illustrative

Coldcard Wallet Losses Climb to $70 Million as More Addresses Confirmed Drained

Total losses tied to a security flaw affecting Coldcard hardware wallets have grown to about $70 million, according to new findings from Galaxy Research, which said nearly 1,200 addresses were fully drained of over 1,000 bitcoin.

Laurisa
By Laurisa

Junior Author · August 1, 2026

2 min
Key takeaways
Total losses tied to a security flaw affecting Coldcard hardware wallets have grown to about $70 million, according to new findings from Galaxy Research, which said nearly 1,200 addresses were fully drained of over 1,000 bitcoin.
Scope of the Breach Expands Galaxy Research reported that 1,196 addresses were drained of 1,082.65 BTC, worth roughly $70.2 million, between 01:10 and 01:51 UTC on July 30.
The firm mapped the fund flows based on a pattern identified by engineers at Block and shared with the wider security community, concluding that the same attacker was responsible for all the affected addresses.

Total losses tied to a security flaw affecting Coldcard hardware wallets have grown to about $70 million, according to new findings from Galaxy Research, which said nearly 1,200 addresses were fully drained of over 1,000 bitcoin.

Scope of the Breach Expands

Galaxy Research reported that 1,196 addresses were drained of 1,082.65 BTC, worth roughly $70.2 million, between 01:10 and 01:51 UTC on July 30. The firm mapped the fund flows based on a pattern identified by engineers at Block and shared with the wider security community, concluding that the same attacker was responsible for all the affected addresses.

Coinkite Widens Its Warning and Issues Fixes

Coldcard maker Coinkite initially warned users who generated a seed on a Mk3 device running firmware version 4.0.1 or later that their funds could be at risk. The company later extended that warning to include certain Mk4, Mk5, and Coldcard Q firmware versions, and released emergency updates for all affected models. Coinkite CEO Rodolfo Novak, known as NVK, apologized publicly and said the company takes full accountability for the bug slipping past its review process.

AI-Assisted Discovery Raises New Concerns

Novak suggested the vulnerability may have been found using artificial intelligence, calling it a sign of a new security landscape where AI-assisted code review can uncover hidden flaws faster than traditional expert analysis, potentially giving attackers an edge.

Galaxy Research cautioned that future attacks remain possible on any Coldcard-generated address, since compromised transactions look identical to normal wallet activity. Coinkite has urged affected users to update their firmware, generate a new seed, test it with a small transaction first, and retain their old backup until the transfer is confirmed complete.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Laurisa
Laurisa

Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.