Galaxy: $70M in Bitcoin Stolen from 1,196 Coldcard Wallets Hours Before Flaw Was Disclosed
AI Market Summary
Galaxy Research reports 1,082.65 BTC (~$70.2M) drained from 1,196 Coldcard Mk3 wallets via an RNG flaw in specific firmware versions, occurring ~30 hours before public disclosure. The incident undermines confidence in hardware-wallet key generation and highlights operational risks for long-dormant holders. Short-term, the news can elevate perceived custody risk, increase security-driven fund movements, and weigh on broader crypto sentiment.
Impact level
● Medium
Affected assets
BTC/USDT-2.71%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Hardware wallets are marketed as the safest way to store crypto: keep private keys offline and out of reach. For some Coldcard Mk3 users, that promise broke down at a steep cost.
Galaxy Research says attackers siphoned 1,082.65 BTC—about $70.2 million—from 1,196 Coldcard wallets in roughly 41 minutes on July 30, 2026. The sweep occurred about 30 hours before Coinkite, Coldcard's manufacturer, publicly disclosed a critical firmware vulnerability.
The issue traces to the device's random number generator (RNG) in Coldcard Mk3 firmware versions 4.0.1 through 5.0.3. RNG quality is central to wallet security because it underpins recovery seed generation. If the RNG output is predictable, the seed can be inferred and private keys can be derived without physical access to the device.
Block's engineering team separately pinpointed the root cause and published a technical report the same day Coinkite issued its security advisory. Both disclosures were dated July 30, 2026—after the wallets had already been emptied. Coinkite said the vulnerability did not affect all Coldcard devices, only units running the impacted firmware versions, and urged users to generate brand-new recovery seeds and move funds immediately.
Galaxy highlighted the operation's speed: sweeping nearly 1,200 wallets and more than $70 million in BTC in 41 minutes points to automation, prior reconnaissance, and a prepared set of vulnerable addresses. On-chain activity indicates many source wallets had been dormant for long periods, suggesting long-term holders who had set up their devices years earlier and left funds untouched. After the theft began, proceeds were quickly consolidated; Galaxy flagged one address that received about 594 BTC from the sweep.
The timing—funds drained roughly 30 hours before public disclosure—adds a lingering question for security researchers: who was aware of the RNG flaw, and when? One possibility is that the attacker independently identified the weakness and acted before Coinkite or Block went public. Neither Coinkite nor Galaxy has alleged misconduct in the disclosure process, and Coinkite's advisory did not claim prior attacker knowledge.
For hardware wallet users, the episode underscores that firmware updates are not optional housekeeping. RNG failures can be existential because they compromise the foundation of key generation. Users are advised to confirm their firmware versions, monitor manufacturer security advisories, and take immediate action if their devices are affected. The scale and coordination of the $70.2 million sweep also signals a highly capable adversary, with the expertise to exploit an RNG flaw and the infrastructure to automate near-simultaneous drains across 1,196 wallets.