The cryptocurrency community is reeling from the revelation that the estimated losses stemming from a critical wallet incident involving Coldcard hardware wallets have surged to over $70 million. This dramatic increase comes after a comprehensive on-chain analysis conducted by Galaxy Research, the dedicated research arm of crypto investment titan Galaxy Digital. Their meticulous investigation uncovered a significantly broader scope of affected funds and addresses than initially reported, shedding new light on the severity and coordinated nature of the breach.

Galaxy Research’s deep dive into the Bitcoin blockchain identified a staggering 1,196 unique addresses that collectively lost 1,082.65 Bitcoin. At the time these illicit transactions occurred, the total value of the stolen funds was approximately $70.2 million. This extensive analysis meticulously traced the movement of these Bitcoin between 1:10 AM and 1:51 AM UTC on July 30, spanning across Bitcoin blocks 960,183 to 960,191. Crucially, this period of significant unauthorized activity predates Coldcard’s official security advisory by roughly 30 hours, indicating that the attackers had a substantial head start before the vulnerability was publicly acknowledged. The findings, first disseminated via an X (formerly Twitter) post by @glxyresearch on Friday, Aug 1, 2026, underscored the critical role of on-chain forensics in understanding and responding to large-scale crypto security incidents.

The updated figures from Galaxy Research represent a stark expansion of earlier, preliminary estimates that had painted a less severe, though still concerning, picture. Previously, Rob Hamilton, CEO and co-founder of blockchain security firm AnchorWatch, had conducted an initial analysis of the Coldcard incident. Hamilton’s early findings suggested that approximately 594.48 Bitcoin, valued at around $38 million, had been moved across 500 transactions within a much narrower three-block window. While Hamilton’s swift response provided crucial early warnings, Galaxy Research’s subsequent, more exhaustive examination revealed that the actual impact was nearly double the initial estimate in terms of Bitcoin quantity and monetary value, and more than double the number of affected addresses. This significant discrepancy highlights the challenges in accurately assessing the full scope of a blockchain exploit in its immediate aftermath and the value of persistent, in-depth analytical work.

A key element in Galaxy Research’s ability to identify the extended range of compromised funds was the discovery of a distinctive pattern shared by the identified transactions. According to subsequent posts from @glxyresearch, these transactions exhibited two primary characteristics: identical transaction fees of 30 satoshis per virtual byte and the complete absence of change outputs. The uniformity of the 30 satoshis per virtual byte fee is highly unusual for organic, user-initiated transactions, which typically exhibit more variability. Such a precise and consistent fee rate across a large number of transactions is a strong indicator of automated, coordinated activity, suggesting that the attacker used a script or bot to sweep funds rapidly. Furthermore, the lack of "change outputs" is a critical forensic clue. In a typical Bitcoin transaction where a user spends less than the total amount of an input, the remaining funds are sent back to a "change address" controlled by the sender. The absence of these change outputs implies that the entire balance of each compromised address was drained in a single sweep, a common tactic employed by attackers to consolidate stolen funds. While this distinct "fingerprint" proved invaluable in identifying the initial wave of attacks, Galaxy Research cautioned that future attack vectors or subsequent fund movements might not necessarily adhere to the same pattern, necessitating ongoing vigilance and diverse analytical approaches.

In response to the escalating crisis, Rodolfo Novak, co-founder of Coinkite, the company behind the Coldcard hardware wallet, publicly addressed the issue on Friday via an X post. Novak acknowledged the gravity of the situation, stating that Coinkite takes full responsibility for the firmware bug that led to the extensive losses. This acceptance of responsibility, while commendable, underscores the profound impact such a vulnerability can have on user trust, especially for a device marketed as a bastion of security for self-custody. Coldcard has long been revered within the Bitcoin community for its robust security features, including its air-gapped nature, secure element, and emphasis on user control, making this incident particularly alarming.

Novak further detailed the immediate steps Coinkite had taken to mitigate the ongoing threat. The company promptly released a hotfix designed to remove what was described as a "software fallback path." While specific technical details of this fallback path were not fully elaborated, such a mechanism typically refers to a secondary, potentially less secure, software routine that the hardware wallet might revert to under certain conditions, bypassing its primary secure hardware components. Exploiting such a path could theoretically allow an attacker to gain access to or compromise the private keys generated or managed by the device. The hotfix aims to eliminate this vulnerability, preventing new instances of the exploit from occurring on updated devices.

However, Novak issued a critical warning that resonated deeply with the affected user base: the hotfix, while crucial for future security, does not protect seeds that were generated on vulnerable firmware. This means that any user who initialized their Coldcard device and generated their Bitcoin seed phrase using the compromised firmware remains at risk, even after updating their device. The core issue lies in the compromised seed itself, which could have been generated in a way that makes its derived private keys predictable or extractable by the attacker, or perhaps exposed during the generation process via the "software fallback path." Consequently, Novak strongly advised all users who generated their seeds on the vulnerable firmware to immediately move their funds to a completely new seed generated on an updated, secure device. This necessitates generating a new seed phrase, creating new Bitcoin addresses, and then transferring all existing funds from the old, potentially compromised addresses to these new, secure ones. This process, while cumbersome and potentially stressful, is the only way to ensure the long-term safety of their Bitcoin holdings.

The Coldcard incident casts a long shadow over the hardware wallet industry and the broader cryptocurrency ecosystem. Hardware wallets are generally considered the gold standard for self-custody, providing an isolated, air-gapped environment for storing private keys, thus protecting them from online threats. The fact that such a respected device could suffer a vulnerability leading to multi-million dollar losses highlights that even the most advanced security solutions are not impervious to flaws. This incident serves as a stark reminder of the continuous cat-and-mouse game between security researchers and malicious actors, emphasizing the critical importance of rigorous security audits, transparent bug bounty programs, and swift, decisive action from manufacturers when vulnerabilities are discovered.

For users, this incident underscores the paramount importance of staying informed, diligently following security advisories from reputable hardware wallet providers, and understanding the nuances of their chosen security tools. While hardware wallets significantly enhance security, they are not a set-it-and-forget-it solution. Regular firmware updates are essential, and in cases like this, proactive steps such as migrating funds to new seeds are non-negotiable. Furthermore, the incident highlights the power and necessity of on-chain analysis. Without the sophisticated forensic capabilities of firms like Galaxy Research, the true extent of such a breach might remain underestimated, hindering effective response and recovery efforts.

The Coldcard saga is a painful but potent lesson in the ever-evolving landscape of cryptocurrency security. It reinforces the principle that while the blockchain itself is immutable and secure, the interfaces and devices used to interact with it can harbor vulnerabilities. As the industry matures, the focus will undoubtedly intensify on comprehensive security protocols, independent audits, and robust incident response frameworks to protect users’ valuable digital assets. For now, the crypto community watches closely as Coldcard navigates this crisis, hoping for a full resolution and a restoration of trust in one of its most critical security tools.