Over 1,000 bitcoins, valued at approximately $70 million, were stolen from 1,196 Coldcard wallets within a brief 41-minute timeframe on July 30. This figure is nearly double the initial loss reported.

Galaxy Research detailed the incident on Friday, revealing that 1,082.65 BTC was taken between 01:10 and 01:51 UTC across six blocks, indicating that the transactions were likely batched rather than sent continuously.

The stolen funds are currently held in four separate addresses, which have remained inactive. The earlier reports only identified one of these addresses, leading to the revised total loss figure.

Although this breach is smaller compared to other significant thefts this year, the method of attack raises serious concerns, making it particularly noteworthy.

Why the Coldcard Wallet Breach is Uniquely Concerning

Typically, crypto theft involves compromising a system to gain access to the keys. This could occur through a breach of an exchange, phishing for keys, or exploiting vulnerabilities in contracts. Hardware wallets like Coldcard are designed to prevent such access by keeping keys offline, theoretically making them secure.

When generating a wallet, the device is expected to create a seed phrase that is nearly impossible to guess due to its complexity. However, a firmware flaw in certain Coldcard devices allowed for predictable seed phrase generation, enabling attackers to reconstruct private keys without any direct access to the wallets.

Instead of utilizing a high-quality randomness generator as intended, Coldcard's firmware reverted to a basic software alternative that used the device's serial number and clock data as the seed. This resulted in a drastically reduced range of potential keys, making them vulnerable to computation.

Security teams identified that the key generation on older versions of Coldcard (Mk2 and Mk3) was particularly susceptible, while the newer Mk4, Q, and Mk5 models were estimated to produce around four billion possible keys—a number manageable for attackers.

Attackers can create candidate seeds on their own devices, derive potential addresses, and verify these against the public blockchain without any interaction with the victim’s wallet.

Galaxy's analysis shows that of the wallets affected, 1,183 used the modern native SegWit address format, with others utilizing older formats. This systematic approach to enumeration suggests a deliberate and thorough attack strategy.

Galaxy Research cautioned that further attacks might occur if wallet owners do not relocate their funds.

The Attack May Not Be Over

Coinkite, the manufacturer of Coldcard, has issued warnings to owners of Mk3 devices, stating that newer models are not affected. Nevertheless, reports indicate that Mk2, Mk4, Q, and Mk5 models could also be at risk. Until this issue is fully addressed, users of the compromised firmware need to assume their wallets may be vulnerable.

Interestingly, the attacker made a critical error. Clay Garrett from Block noted that the perpetrator utilized a paid service from a well-known blockchain data provider to monitor the source addresses during the thefts. Internal logs from the provider could link the attacker's actions with remarkable precision, down to the exact number and timing of requests.

1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source… https://t.co/l5McyhhcNn

— Clay Garrett (@clay_garrett) July 31, 2026

The provider appears to have delivered standard services without flagging the unusual nature of these requests. Block has shared this information with law enforcement.

While cold storage solutions promise unguessable keys, this incident reveals that the assumption of physical security may no longer be sufficient. Research from Anthropic highlighted vulnerabilities in post-quantum algorithms, demonstrating how quickly security can deteriorate.

In summary, ensuring the safety of keys has become a more complex challenge than ever before.