Loading market data...

Attacker Drains $30M From Coldcard Wallets in 10 Minutes, Chainalysis Reports

Attacker Drains $30M From Coldcard Wallets in 10 Minutes, Chainalysis Reports

An attacker stole roughly $30 million from Coldcard wallets in just 10 minutes by targeting the largest holdings first, according to blockchain analytics firm Chainalysis. The total haul exceeded $38 million and hit 500 wallets, exposing lasting risks for seeds created on vulnerable firmware. Chainalysis published the details on July 31, but the attack itself appears to have happened earlier — the firm didn't specify a date.

How the sweep worked

The attacker didn't go after small balances. Chainalysis found they prioritized the biggest Coldcard wallets, draining them in a rapid, automated sweep. Within 10 minutes, $30 million was gone. The final tally climbed past $38 million as more wallets were hit. The method suggests the attacker had a list of high-value targets and a way to crack or bypass the seed security.

The firmware vulnerability

Chainalysis pointed to risks for seeds created on vulnerable firmware. Coldcard wallets are known for their security-focused design, but if the firmware used to generate the seed phrase had a flaw, the attacker could have exploited it. The firm didn't name a specific firmware version, but the implication is clear: users who generated seeds on older or compromised firmware may have had their keys exposed.

What Coldcard users should know

Coldcard has not publicly responded as of press time. The attack raises questions about how many users are still running outdated firmware. For anyone who created a seed on a Coldcard device more than a year ago, the safest move is to generate a new seed on the latest firmware and move funds. Chainalysis didn't say whether the attacker used a known vulnerability or a zero-day, but the speed of the sweep suggests a pre-planned exploit.

Chainalysis has shared its findings with law enforcement, but no arrests have been announced. The firm is likely still tracing the stolen funds. For the broader crypto community, the incident is a reminder that hardware wallet security depends on the entire supply chain — including the firmware used at setup. Coldcard users are waiting for an official statement and, ideally, a patch or a clear advisory on which firmware versions are safe.