Crypto

Galaxy Research Uncovers $70M Coldcard Exploit as Bitcoin Wallet Vulnerability Scope Expands

Blockchain sleuths trace 1,082 Bitcoin drained across 1,196 addresses within 41 minutes following a critical firmware flaw in Coinkite hardware wallets.

A major security breach involving Coldcard hardware wallets resulted in the loss of 1,082.65 Bitcoin—valued at approximately $70.2 million at the time of the transfers—dramatically exceeding initial estimates of the exploit.

Analysis conducted by Galaxy Research revealed that the funds were systematically siphoned across 1,196 distinct addresses in a concentrated 41-minute window on July 30. The illicit transfers occurred between 1:10 AM and 1:51 AM UTC, spanning Bitcoin blocks 960,183 through 960,191. This activity took place roughly 30 hours before hardware manufacturer Coinkite issued its initial security advisory to the public.

The updated findings significantly revise early assessments of the vulnerability. Initial data published by Rob Hamilton, chief executive of Bitcoin insurance firm AnchorWatch, suggested a smaller breach involving 594.48 Bitcoin—worth roughly $38 million—executed across 500 transactions in a three-block span.

Researchers identified a uniform on-chain signature during the initial attack vector. Each transaction was processed with an identical fee rate of 30 satoshis per virtual byte and contained zero change outputs, indicating automated scripts sweeping entire unspent transaction outputs. While this exact footprint helped trace the primary breach, analysts cautioned that subsequent exploits targeting affected addresses might employ varied transaction parameters.

In Bitcoin transaction mechanics, change outputs return remaining funds to the sender after paying the intended recipient and miner fees. The absence of change outputs in these transfers confirms that compromised wallets were emptied completely in single sweeps.

Coinkite co-founder Rodolfo Novak publicly acknowledged responsibility for the underlying firmware bug, confirming that a software fallback path created the vulnerability during key generation routines. Hardware wallets typically rely on dedicated physical entropy sources to construct cryptographic seed phrases. When fallback software mechanisms trigger improperly, entropy can be compromised, leading to predictable or weak keys that attackers can calculate off-chain.

Coinkite has since dispatched an emergency hotfix to strip out the faulty fallback routine. However, Novak emphasized that updating the device firmware does not remediate keys generated under the vulnerable software version. Users who created recovery seeds on affected firmware remain exposed until they transfer all assets to entirely new seeds generated on patched devices.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button