A vulnerability in Coldcard hardware wallets has led to the theft of over 1,367 Bitcoin, worth roughly $89 million, according to blockchain analytics firm Galaxy Research. The exploit, which Coinkite warned about on July 30, stems from a software error that produced seed phrases with insufficient randomness, allowing attackers to drain wallets generated with affected firmware.
Three attack waves hit 4,585 addresses
Galaxy Research reported three distinct attack waves targeting 4,585 addresses. The stolen Bitcoin remains in attacker-controlled wallets, with smaller opportunistic thefts moving through peel chains, cross-chain services, and offshore casinos. The firm noted that US large language model guardrails hindered its tracing efforts, forcing investigators to switch to an open-source Chinese model instead.
On-chain activity spikes after disclosure
The public disclosure triggered a flurry of on-chain movement. CryptoQuant data shows transactions involving outputs of less than 1 BTC reached 39,600 BTC on July 31 — the largest daily total since November 2022, when 39,900 BTC moved after the FTX collapse. Bitcoin daily active addresses jumped from about 645,000 on July 30 to nearly 1 million on July 31, the highest since Dec. 10, 2024. Exchange deposits involving transfers below 10 BTC climbed to 7,300 BTC, their highest level since Feb. 6.
CryptoQuant analyst JA Maartunn noted that 77,402 BTC from older unspent-transaction-output bands moved since the vulnerability became public, but cautioned against interpreting this as broad investor capitulation. Meanwhile, Santiment reported Bitcoin's ratio of positive to negative commentary fell to 0.58 bullish comments per bearish one — the lowest level since modern social tracking began.
Coinkite releases fix, but old seeds are toast
Coinkite released fixed firmware for affected Coldcard models, but existing affected seed phrases cannot be repaired through an update. Users who generated wallets with the vulnerable firmware must create new wallets from scratch. The company first warned of the issue on July 30, urging users to move funds immediately.
The stolen Bitcoin remains in attacker-controlled addresses, with smaller amounts still trickling through peel chains and casinos. Coinkite has urged users to generate new wallets with the updated firmware, but the funds already lost are unlikely to be recovered.




