Galaxy Research Raises Coldcard Bitcoin Loss Estimate to About $70M

AI Market Summary
Galaxy Research expanded the estimated scope of the Coldcard incident to 1,082.65 BTC (~$70.2M) swept from 1,196 addresses in a 41-minute burst, about 30 hours before Coldcard's first advisory. The larger loss estimate and evidence of automated, patterned sweeps heighten operational risk concerns around self-custody hardware wallets, potentially pressuring near-term sentiment and prompting defensive fund migrations.
Impact level
● Medium
Affected assets
BTC/USDT-1.10%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Galaxy Research, the analytics and research unit of Galaxy Digital, says it has widened the onchain picture of the Coldcard wallet incident after identifying 1,196 impacted Bitcoin addresses. Based on its tracing, those addresses saw 1,082.65 BTC moved out within a 41-minute burst—valued at roughly $70.2 million at the time of the transactions. Galaxy said the activity occurred between 1:10 a.m. and 1:51 a.m. UTC on July 30, spanning blocks 960,183 through 960,191. The window is notable because it falls about 30 hours before Coldcard issued its first public security advisory. Galaxy's findings extend earlier public estimates and aim to clarify what attackers may have executed soon after vulnerable wallets generated seed phrases. Key points - Galaxy Research linked 1,196 addresses to the incident and attributed losses of 1,082.65 BTC over a 41-minute period. - The transfers occurred between 1:10 a.m. and 1:51 a.m. UTC on July 30 across blocks 960,183–960,191, roughly 30 hours before Coldcard's initial advisory. - A prior estimate from AnchorWatch CEO and cofounder Rob Hamilton pointed to 594.48 BTC moving through a tighter three-block slice of activity. - Galaxy said the transactions it clustered share a distinctive onchain signature: identical fees of 30 satoshis per virtual byte and no change outputs, though it warned later sweeps may not follow the same pattern. A broader attack map Galaxy said the transfers appear concentrated in a short run of blocks, suggesting automation and repeated transaction construction rather than sporadic manual movement. The firm values the 1,082.65 BTC at about $70.2 million at the time the funds were swept. The timing also points to rapid attacker execution: Galaxy's traced window begins roughly a day before the first public advisory from Coldcard, implying the initial sweep occurred early and ahead of the broader response cycle. Pattern matching helps—but may not capture everything In follow-up analysis, Galaxy said the clustered sweep transactions share two consistent traits: a 30 sat/vB fee rate and no change outputs. Those features can serve as an onchain fingerprint for investigators, supporting clustering efforts and reducing the risk of accidentally grouping unrelated transfers. Galaxy cautioned that the same fingerprint may not hold for subsequent activity tied to Coldcard-generated addresses. If later sweeps use different fees or output behavior, totals based only on the initial recognizable structure could understate the full impact. Earlier estimates relied on a narrower window Before Galaxy's expanded mapping, Hamilton estimated 594.48 BTC (about $38 million at the time) moved across 500 transactions within a three-block window. Galaxy's broader address set and longer slice of the July 30 burst nearly doubles the BTC attributed to the sweep activity. The gap between estimates highlights a recurring incident-response challenge in self-custody systems: full scoping often requires days of tracing, clustering, and validation, especially when attackers reuse transaction logic across many destinations. Coinkite acknowledges a firmware bug, urges seed migration Coldcard manufacturer Coinkite has acknowledged responsibility for the underlying issue. In a Friday post on X, cofounder Rodolfo Novak said the company is working to determine the full scope and has released a hotfix intended to remove a software fallback path. Novak also emphasized a key limitation: the update does not secure seed phrases generated on the vulnerable firmware. Users who created seed phrases during the affected period have been advised to move funds to a new seed. The guidance reflects a core principle of seed compromise response: updating firmware does not retroactively protect keys already generated under flawed conditions. What users should watch next Galaxy's sweep pattern provides a clearer basis for tracking related flows, but its warning that future activity may not match the same signature leaves room for additional, harder-to-identify movements. Users who suspect they generated seeds on vulnerable firmware are advised to migrate any remaining balances to newly generated seeds and monitor addresses for further activity.