The cryptocurrency community is reeling as the financial fallout from the recent Coldcard wallet incident continues to escalate. Recent on-chain investigations have revealed a significantly larger impact than initially thought, sending shockwaves through hardware wallet users who rely on these devices for top-tier security.
Understanding the Scope of the Coldcard Wallet Exploit
Galaxy Research, the analytical division of crypto investment giant Galaxy Digital, has provided a sobering update on the recent security breach. According to their comprehensive on-chain analysis, the exploit drained 1,082.65 Bitcoin from 1,196 compromised addresses. At the time the funds were moved, this staggering loss was valued at approximately $70.2 million. The attack was executed with alarming speed, occurring within a narrow 41-minute window on July 30 between 1:10 AM and 1:51 AM UTC. This malicious activity spanned across blocks 960,183 to 960,191, striking a full 30 hours before Coldcard published its initial security advisory.
This new data paints a much grimmer picture than early reports suggested. Previously, preliminary analysis conducted by Rob Hamilton, CEO and co-founder of AnchorWatch, estimated that the attacker had moved 594.48 Bitcoin, worth around $38 million, across 500 transactions within a much smaller three-block window. Galaxy Research also identified a distinct fingerprint left by the attacker during this initial wave. The fraudulent transactions shared identical network fees of 30 satoshis per virtual byte and featured absolutely no change outputs. While this specific pattern makes the initial attack easy to identify on the blockchain, analysts warn that future exploits targeting vulnerable Coldcard-generated addresses might adopt entirely different tactics to avoid detection.
Coinkite Responds with a Critical Hotfix and Urgent Advice
Facing mounting pressure from the crypto community, the team behind Coldcard has stepped forward to address the crisis. Rodolfo Novak, co-founder of Coinkite, took to the social media platform X to formally acknowledge the situation. Novak stated that the company is taking full responsibility for the underlying firmware bug that led to the devastating exploit and reassured users that they are working to determine the complete scope of the vulnerability.
In an effort to stop the bleeding, Coinkite has officially released a hotfix designed to eliminate the software fallback path that hackers exploited. However, the company has issued a stark warning regarding the limitations of this software patch. The update alone does not secure wallets that were already compromised by the flawed firmware. For anyone who generated their seed phrases on the vulnerable firmware version, simply updating the device is not enough. Novak strongly advises these users to immediately generate a completely new seed phrase on a secure device and transfer all their remaining funds to ensure their Bitcoin is safe from further attacks.