Coldcard Bitcoin loss estimate rises to $70M after Galaxy analysis
Galaxy Research has significantly increased the estimated Bitcoin losses from a Coldcard hardware wallet incident to 1,082.65 BTC, valued at approximately $70.2 million. This new analysis expands upon earlier estimates, identifying more affected addresses and transactions.
Intelligence analysis by Gemini 2.5 Flash

A recent analysis by Galaxy Research indicates that the Coldcard hardware wallet incident resulted in the loss of over 1,000 Bitcoin, a substantial increase from previous estimates. The firm identified a distinct transaction pattern across nearly 1,200 addresses, revealing a broader scope of the security breach that occurred before Coldcard issued its advisory.
Imagine you have a special digital piggy bank called Coldcard to keep your Bitcoin safe, like a super-secure vault. But a tiny mistake in the instructions for making some of these vaults meant a sneaky trick could let someone take money out. Now, a detective agency called Galaxy found out that way more money was taken than first thought, about $70 million! The company that makes the piggy bank is fixing the instructions, but if you made your piggy bank with the old, faulty instructions, you need to move your money to a brand new, fixed one right away.
Analysis
Uncovering the Full Extent of Loss
Galaxy Research, the analytical arm of Galaxy Digital, has provided a more comprehensive assessment of the Coldcard hardware wallet incident, revealing a significantly larger scale of Bitcoin losses than initially understood. Their investigation identified 1,196 distinct addresses that collectively lost 1,082.65 Bitcoin, amounting to approximately $70.2 million at the time of the transactions. This figure dramatically surpasses the preliminary estimate by AnchorWatch CEO Rob Hamilton, which had pegged the losses at around 594.48 Bitcoin, or $38 million.
Galaxy's methodology involved tracing Bitcoin movements within a specific 41-minute window on July 30, across blocks 960,183 to 960,191. Crucially, this activity occurred roughly 30 hours before Coldcard's first public security advisory. The research team identified a consistent on-chain pattern among the affected transactions, characterized by identical 30 satoshis per virtual byte fees and the absence of change outputs, which served as a unique fingerprint for the initial attack.
The Firmware Flaw and Coinkite's Response
The incident stems from a firmware bug within Coldcard wallets, for which Coinkite, the manufacturer, has taken responsibility. Co-founder Rodolfo Novak acknowledged the issue and confirmed that the company is actively working to ascertain the full scope of the problem. In response to the vulnerability, Coinkite promptly released a hotfix designed to eliminate the problematic software fallback path that enabled the exploit.
However, Novak issued a critical warning to users: the hotfix does not retroactively protect seeds that were generated using the vulnerable firmware. This means that users who created their wallet seeds on the compromised software remain at risk even after updating. Consequently, Coinkite has strongly advised these users to transfer their funds to a new seed generated on the updated, secure firmware to prevent further losses.
Broader Implications for Hardware Wallet Security
This Coldcard incident serves as a stark reminder of the inherent risks associated with self-custody and the critical importance of hardware wallet security. Even devices designed for maximum protection can harbor vulnerabilities, emphasizing that no solution is entirely foolproof. The significant financial loss highlights the potential consequences when such flaws are exploited, impacting a large number of users.
The event also underscores the ongoing need for rigorous security audits, transparent communication from hardware wallet manufacturers, and proactive user education. For the broader cryptocurrency ecosystem, it reinforces the principle that users bear ultimate responsibility for their digital assets, necessitating constant vigilance, adherence to best security practices, and prompt action when advisories are issued. The incident will likely prompt both users and manufacturers to re-evaluate security protocols and potentially accelerate the development of more resilient and verifiable hardware solutions.
Key points
- Galaxy Research identified 1,196 addresses that lost 1,082.65 Bitcoin, valued at $70.2 million, in a Coldcard wallet incident.
- The losses occurred within a 41-minute window on July 30, before Coldcard's security advisory was published.
- The transactions shared a distinct on-chain pattern, including identical fees and no change outputs.
- Coinkite, Coldcard's manufacturer, has taken responsibility for the firmware bug and released a hotfix.
- Users who generated seeds on vulnerable firmware are advised to move their funds to a new, secure seed.
The incident could lead to enhanced security practices across the hardware wallet industry, prompting more thorough audits and faster response mechanisms for vulnerabilities. Increased user awareness about seed generation and firmware updates may also improve overall self-custody security.
The significant loss of funds could erode user trust in hardware wallets, potentially pushing some users towards centralized exchanges despite their own risks. There's also a risk that future attacks might not follow the same identifiable pattern, making detection and prevention more challenging.



