All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Bitcoin cold wallets drained of $70M in firmware flaw attack

Created at 1 Aug · 6:06 AM1 source↑ Market-relevant
IN SHORT

Over 1,000 Bitcoin, valued at approximately $70 million, were stolen from 1,196 Coldcard hardware wallets due to a firmware vulnerability. Attackers exploited a flaw that made seed phrases enumerable, allowing them to reconstruct private keys without physical access to the devices.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

1,082.65 BTCBitcoin stolen
$70 millionValue of stolen Bitcoin
1,196Number of affected Coldcard wallets
41 minutesDuration of theft window
4Addresses holding stolen funds
4 billionPossible keys on affected Mk4, Q, Mk5 models

Who's Involved

Coldcard
Hardware wallet brand affected by firmware flaw
Galaxy Research
Mapped the full event and identified the theft pattern
Coinkite
Maker of Coldcard wallets, issued warnings
Block
Reported on affected models and attacker's mistake
Clay Garrett
Stated attacker used a paid account at a blockchain data provider
Bitcoin cold wallets drained of $70M in firmware flaw attack

↳ Why This Matters

This exploit undermines the fundamental security of hardware wallets, which are relied upon to protect digital assets by keeping private keys offline. The inability for users to verify if their wallets are compromised creates ongoing risk and highlights the evolving sophistication of crypto theft methods.

Key facts

  • Over 1,000 Bitcoin, valued at approximately $70 million, were stolen from 1,196 Coldcard wallets.
  • A firmware flaw in specific Coldcard models allowed attackers to reconstruct private keys by making seed phrases enumerable.
  • The attack occurred over a 41-minute window on July 30.
  • The stolen funds have not been moved and are held in four addresses.
  • Owners of affected wallets cannot reliably determine if their seeds were generated on vulnerable firmware.
  • The vulnerability affected Coldcard Mk2, Mk3, Mk4, Q, and Mk5 models.

More than 1,000 Bitcoin, valued at approximately $70 million, were stolen from 1,196 Coldcard hardware wallets in a 41-minute period on July 30. Researchers discovered that a firmware flaw in certain Coldcard models allowed attackers to computationally enumerate seed phrases, enabling them to reconstruct private keys without ever physically interacting with the devices. This exploit is significant because it bypasses the core security promise of hardware wallets, which is to keep private keys isolated from online threats. The stolen funds are currently held in four addresses and have not been moved. Security firms warn that owners of affected wallets cannot definitively determine if their seeds were generated on vulnerable firmware, suggesting further attacks are possible. Investigators are tracing the attacker using logs from a blockchain data provider. Coinkite has issued warnings for Mk3 owners and stated newer devices are unaffected, while reports indicate Mk2, Mk4, Q, and Mk5 models are also in scope. The attacker reportedly used a paid account with a blockchain data provider to query source addresses during the theft.

Frequently asked questions

Over 1,000 Bitcoin, valued at approximately $70 million, was stolen from 1,196 Coldcard wallets.

A firmware flaw in certain Coldcard hardware wallets allowed attackers to reconstruct private keys by making seed phrases computationally enumerable.

No, the attackers did not need to physically touch the devices to steal the funds.

Reports indicate that Mk2, Mk3, Mk4, Q, and Mk5 models are affected, though Coinkite has specifically warned Mk3 owners and stated newer devices are unaffected.

No, owners cannot reliably determine if their seed phrases were generated on vulnerable firmware.

What Happens Next

01Investigators continue to trace the attacker through blockchain data provider logs.
02Owners of affected Coldcard wallets are advised to assume their seeds may be compromised.
03Further waves of attacks are possible if owners do not move their funds.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

More than 1,000 Bitcoin, worth about $70 million, was drained from 1,196 Coldcard wallets.
Researchers identified a firmware flaw in certain Coldcard hardware wallets.
The flaw allowed attackers to reconstruct private keys by making seed phrases computationally enumerable.
Attackers did not need to physically touch the devices to steal the funds.
The stolen funds remain in four addresses and have not moved.
Security firms warn that more wallets could be affected.
Investigators are tracing the attacker through logs from a blockchain data provider.
Coinkite has warned Mk3 owners and stated newer devices are unaffected, while Block's report includes Mk2, Mk4, Q, and Mk5 models.

Sources

T1
How bitcoin cold wallets lost $70 million in an attack that never touched the devicesCoinDesk

Related Stories

Coldcard Bitcoin Thief Likely Used Top Blockchain Services Provider
31 Jul · 3:25 PM
FTX users receive funds, Citadel buys stock, Coldcard warns users
31 Jul · 8:06 PM
Texans Lost $57M to Crypto Kiosk Scams in 2025, Lawmakers Consider Ban
31 Jul · 11:21 AM
AMLBot launches AI Tracer for self-service blockchain investigations
31 Jul · 2:16 PM
XRP Ledger upgrade reintroduces features previously pulled for critical bugs
1 Aug · 6:16 AM