Coldcard-Linked Bitcoin Drains Hit About $70M After Seed-Generation Firmware Flaw
AI Market Summary
Galaxy Research linked ~1,082.65 BTC (~$70.2M) drained from 1,196 addresses to a Coldcard seed-generation firmware vulnerability. Coinkite expanded its advisory across multiple devices and issued emergency updates, but the incident underscores hardware-wallet operational risk and can pressure near-term custody confidence. Traders may see elevated event-driven derisking as users rotate seeds and shift balances while the scope and containment of the exploit are assessed.
Impact level
● Medium
Affected assets
BTC/USDT-2.68%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Galaxy Research reported that 1,196 addresses were emptied for a total of 1,082.65 BTC—about $70.2 million—between 01:10:20 and 01:51:26 UTC on July 30.
The firm tied the outflows to a Coldcard seed-generation vulnerability, citing a transaction pattern first flagged by engineers at Block and shared by Clay Garrett.
Coinkite initially warned that users who generated seeds on Coldcard Mk3 devices running firmware version 4.0.1 or later could be at risk. The company later broadened the advisory to certain Mk4, Mk5 and Coldcard Q firmware versions and issued emergency firmware updates. On Friday, Coinkite CEO Rodolfo Novak (NVK) apologized and said the company is taking full responsibility for the firmware bug.
Why it matters: Weaknesses in seed generation can turn a device-level firmware issue into an immediate custody risk for users holding funds in affected wallets.
Market sentiment: Bearish, stress-on, event-driven, de-risking. Traders may view the linkage of more than 1,000 BTC in drained funds to a Coldcard vulnerability as a direct hit to custody confidence.
Similar case: In 2022, Solana developers traced a wallet drain to Slope mobile wallets, with nearly 8,000 wallets affected as of 5 a.m. UTC. Slope advised users to create a new seed phrase and transfer assets to a new wallet. The Slope incident involved mobile software wallets; the current episode centers on Coldcard hardware-wallet firmware and Bitcoin seeds.
Ripple effects: Confidence in self-custody can erode if users conclude seed generation is unreliable across impacted devices. Additional drains tied to the affected seed cohorts could prompt users to move funds away from self-custody while rotating wallets. If emergency updates prevent further thefts, losses may remain limited to wallets created with compromised seeds.
Opportunities & risks:
- Opportunities: If Coinkite’s emergency updates and a new-seed process halt new drains, staged transfers—starting with a small test transaction—may provide a safer recovery path.
- Risks: If new attacks emerge on Coldcard-generated addresses, treating older seeds as compromised may reduce exposure to additional custody losses.