Galaxy Research: Coldcard Wallet Flaw Tied to 1,000 BTC in Losses, About $70M
AI Market Summary
Galaxy Research linked ~1,000 BTC (~$70M) of losses to a Coldcard hardware-wallet mnemonic-generation vulnerability affecting multiple models and firmware versions. Coinkite expanded its risk advisory and pushed emergency updates, while acknowledging internal review failures and highlighting AI-assisted discovery as an emerging threat. The incident elevates counterparty and operational-security concerns for self-custody users, potentially dampening near-term risk appetite across crypto.
Impact level
● Medium
Affected assets
BTC/USDT-2.76%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Galaxy Research said Friday that more than 1,000 BTC—worth roughly $70 million—has been moved out of nearly 1,200 addresses, with the transfers believed to be connected to a vulnerability affecting Coldcard hardware wallets.
The disclosure follows a warning issued Thursday by Coinkite, the maker of Coldcard, citing an ongoing issue involving mnemonic phrases generated by the Coldcard Mk3. Coinkite urged users who created seed phrases on an Mk3 running firmware version 4.0.1 or later—released in March 2021—to treat their funds as potentially at risk.
Coinkite later broadened its advisory to certain firmware versions for the Mk4, Mk5 and Coldcard Q, and pushed emergency firmware updates for all impacted models.
Coinkite CEO Rodolfo Novak, known as NVK, apologized Friday and said the company takes full responsibility for the firmware vulnerability, adding that internal review procedures failed to catch the problem. Novak also suggested the flaw may have been uncovered with the help of artificial intelligence, calling it a "sobering reality under the new AI paradigm." He warned that AI-assisted code review can surface vulnerabilities faster than seasoned security professionals, potentially lowering the bar for attackers to exploit weaknesses in publicly available code.