CryptoMag
NEWS Published: AUG 2, 2026, 5:47 PM

Significant Bitcoin Theft Uncovered: $70 Million Lost from Cold Wallets Without Physical Access

Significant Bitcoin Theft Uncovered: $70 Million Lost from Cold Wallets Without Physical Access

On July 30, over 1,000 Bitcoin, equivalent to approximately $70 million, was stolen from 1,196 Coldcard wallets in a shocking incident that lasted just 41 minutes. The scale of the theft, which was nearly double the initial reports, was detailed by Galaxy Research.

The Mechanics of the Attack

Between 01:10 and 01:51 UTC, 1,082.65 BTC was swept away across six blocks, with intervening blocks showing no activity. This indicates that transactions were likely broadcast in batches instead of continuously. The stolen bitcoins were subsequently sent to four addresses, which have shown no activity since.

According to Galaxy’s findings, the owner of the Coldcard wallets fell victim to a fundamental flaw in the device’s seed generation process. Rather than using a robust hardware randomness generator, certain internal settings allowed the Coldcard wallets to produce private keys based on weaker factors, making them vulnerable.

Understanding Coldcard Vulnerabilities

The Coldcard’s firmware was intended to generate a secure seed from a dedicated hardware randomness source. However, an error in the firmware allowed the device to generate seeds based on the chip’s serial number and clock registers, leading to a significant reduction in the complexity of keys produced.

This vulnerability enabled the attacker to recreate the private keys using their own hardware without ever accessing the physical Coldcard devices. Galaxy’s analysis showed that of the compromised wallets, the majority utilized modern native segwit address formats, highlighting the systematic approach of the attacker who could check numerous candidate seeds against the public blockchain.

Potential Future Risks

Galaxy Research has issued a warning, stating that further attacks could occur if affected users do not move their cryptocurrencies. Owners of Coldcard devices currently cannot determine their exposure due to the nature of the vulnerability. Coinkite, the maker of Coldcard, has alerted users of Mk3 devices and issued statements regarding the safety of newer models.

Investigation and Precautions

Interestingly, the attacker made an error by using a paid account at a well-known blockchain data provider for querying source addresses, which could lead to traces of their activities. This finding has been shared with authorities for further investigation.

The Coldcard incident serves as a stark reminder of vulnerabilities in crypto security measures. The promise of cold storage being unguessable does not equate to being unreachable, and as the cost of uncovering such flaws decreases, the need for robust security protocols becomes paramount.

Source: coindesk.com

BTC / ZAR

Bitcoin · Rank #1

R1,411,298.96

-0.25% 24h

24h High
R1,437,479.50
24h Low
R1,393,588.25
Market Cap
R28.34T
Volume 24H
R1.19T

7-day price

View full BTC market Trade

Powered By