Galaxy Research Links $70M Coldcard Wallet Exploit to 1,196 Drained Bitcoin Addresses

AI مارکیٹ کا خلاصہ
Galaxy Research traced a 41-minute drain of 1,082.65 BTC (~$70.2M) from 1,196 Coldcard-linked addresses to a single automated operator, tied to a disclosed firmware vulnerability and followed by emergency updates from Coinkite. The event underscores hardware-wallet implementation risk and potential for follow-on exploits in affected single-signature setups, raising near-term self-custody and counterparty-risk sensitivity across Bitcoin holders.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+0.13%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Galaxy Research says it has identified 1,196 Bitcoin addresses tied to Coldcard hardware wallets that were emptied of 1,082.65 BTC—about $70.2 million—during a 41-minute window on July 30. The firm said the theft unfolded between 01:10:20 UTC and 01:51:26 UTC, spanning six Bitcoin blocks, and occurred before Coinkite publicly disclosed a firmware vulnerability affecting certain Coldcard devices. Galaxy added it found no other transactions matching the same signature over the past 30 days. A consistent on-chain footprint Galaxy reported that each sweep transaction used the same 30.0 sat/vB fee rate and produced no change output. Researchers said the uniform fee and structure set the activity apart from typical consolidation behavior and suggested a single automated operator. The drained addresses included 1,183 native SegWit addresses, seven BIP49 addresses, and six BIP44 addresses. Galaxy said the mix is consistent with automated scanning across multiple derivation paths. The transactions also appeared in bursts rather than a steady stream, with three blocks during the 41-minute span showing no sweep activity. Galaxy said four Bitcoin addresses received the stolen funds, and the consolidated holdings have not moved since. Coinkite issues emergency updates Coinkite initially warned users about an issue involving seeds generated on Coldcard Mk3 devices running firmware version 4.0.1 and later. The company later expanded the advisory to cover certain firmware versions for Mk4, Mk5, and Coldcard Q, and released emergency firmware updates. Coinkite CEO Rodolfo Novak said he takes responsibility for the firmware bug and apologized, adding that internal review processes failed to catch the issue before release. He also suggested artificial intelligence may have helped surface the vulnerability, arguing AI-assisted code review can identify software weaknesses faster than traditional manual checks. More thefts still possible Galaxy warned that additional attacks could occur if users continue to hold funds in affected single-signature Coldcard addresses. The firm cautioned that future thefts may not replicate the same on-chain pattern, noting the observed signature ties to the initial attacker and may not flag later incidents if they resemble legitimate transfers. Galaxy urged users to move funds to trusted custodians or to multisignature self-custody setups. Coinkite advised users to install the updated firmware, generate a new seed, test the wallet with a small transfer, and keep old backups until the migration is complete.