Crypto World
Coldcard Bitcoin Loss Estimate Up to $70M After Galaxy Review
Galaxy Research, the research arm of Galaxy Digital, has expanded the on-chain scope of the Coldcard wallet incident after identifying 1,196 affected Bitcoin addresses. In a 41-minute window, those addresses lost a total of 1,082.65 BTC—worth about $70.2 million at the time the transactions occurred.
The new findings push earlier estimates further, helping clarify what attackers may have executed immediately after the vulnerable wallets generated seeds. Galaxy Research’s tracing covers movements between 1:10 AM and 1:51 AM UTC on July 30 across blocks 960,183 to 960,191, roughly 30 hours before Coldcard published its first security advisory.
Key takeaways
- Galaxy Research identified 1,196 addresses tied to the Coldcard incident and traced losses of 1,082.65 BTC in a 41-minute period.
- The identified activity occurred between 1:10 AM and 1:51 AM UTC on July 30, across blocks 960,183–960,191, about 30 hours before Coldcard’s initial advisory.
- Earlier estimates by AnchorWatch CEO Rob Hamilton were lower, pointing to 594.48 BTC moving through a tighter three-block window.
- Galaxy Research says the transactions share a distinctive pattern on-chain—identical 30 satoshis per virtual byte fees and no change outputs—but future sweeps may differ.
Galaxy Research broadens the attack map
Galaxy Research says it traced the Bitcoin movements tied to the incident to a specific burst of activity on July 30. The research effort focuses on addresses linked to the Coldcard wallet compromise that were swept between 1:10 AM and 1:51 AM UTC.
According to Galaxy Research, the losses accumulated across a short span of blocks—960,183 through 960,191—indicating that the attack likely operated with automation and repeated transaction structure rather than sporadic manual movement. At the time of the outgoing transfers, the 1,082.65 BTC figure was valued at approximately $70.2 million.
The timing is also notable: Galaxy Research’s tracing window began about a day before Coldcard’s first publicly issued security advisory, suggesting that the compromised funds were moved early and that the response cycle lagged behind the initial sweep.
Pattern matching helps confirm related transactions—within limits
In follow-up analysis, Galaxy Research said the identified transactions share a common signature. The company reported that the sweeps used identical 30 satoshis per virtual byte fees and that the transactions contained no change outputs.
Those characteristics are useful for investigators because they provide an on-chain fingerprint for clustering wallet-related activity, which can reduce the chances of misattributing unrelated transfers. Galaxy Research also cautioned that while the initial attack activity is identifiable through this pattern, later attacks against Coldcard-generated addresses may not preserve the same fingerprint.
For users and analysts, this distinction matters: it implies that incident totals based solely on one recognizable transaction structure could undercount additional rounds of activity if those later sweeps differed in fee settings or output behavior.
Earlier estimates were smaller, but based on a narrower window
Before Galaxy Research’s broader mapping, earlier preliminary analysis by AnchorWatch CEO and co-founder Rob Hamilton estimated that 594.48 BTC—about $38 million at the time—moved across 500 transactions within a three-block window.
Hamilton’s figures were drawn from a tighter segment of on-chain activity, reflecting how fast-moving wallet incidents often outpace early investigations. Galaxy Research’s expanded set effectively updates the picture by widening both the address set and the traced timeframe around the July 30 burst, nearly doubling the total BTC attributed to the sweep activity.
The divergence between estimates underscores a common challenge in incident response for self-custody systems: determining full scope can require days of tracing, clustering, and validation—particularly when attackers reuse similar logic across multiple transactions and destinations.
Coinkite acknowledges a firmware bug and advises seed migration
Coldcard’s manufacturer, Coinkite, has taken responsibility for the underlying issue. In an X post on Friday, Coinkite co-founder Rodolfo Novak said the company is working to determine the full scope of the problem and confirmed that it released a hotfix designed to remove a software fallback path.
Novak also emphasized a limitation of the mitigation: the update does not protect seeds generated on the vulnerable firmware. In practical terms, users who created seed phrases during the affected period were advised to move funds to a new seed.
This guidance aligns with the core risk in seed-based compromises—if a vulnerability affects how seed material or related execution paths behave, merely updating firmware may not retroactively secure already-generated keys. The immediate operational implication for affected holders is that recovery requires a transfer to safer key material, not just a device update.
What to watch next for affected users
Galaxy Research’s identification of a common on-chain sweep pattern offers a more structured basis for tracking related activity, but the company’s warning that future attacks may not match the same fingerprint suggests the incident may still evolve in how it appears on-chain. Users concerned about whether they generated seeds with vulnerable firmware should focus on migrating remaining balances to newly generated seeds and continue monitoring for any residual movement tied to addresses linked to the sweep logic.
You must be logged in to post a comment Login