Galaxy Research traced the July 30 attack: 1,082.65 BTC was stolen from 1,196 Coldcard associated addresses.
Galaxy Research pointed out that on July 30, 2024, in just 41 minutes, a total of 1,196 Bitcoin addresses were hollowed out, resulting in a loss of 1,082.65 BTC (approximately US$70.2 million). According to the agency's research, these transactions occurred between 01:10:20 and 01:51:26 UTC time, spanning six Bitcoin blocks, before Coinkite publicly disclosed a firmware vulnerability affecting some Coldcard hardware wallets. Galaxy Research also said it had found no other matching transactions in the past 30 days.
On-chain model reveals transaction correlation
According to Galaxy Research analysis, each stolen transaction paid the same 30.0 sat/vB network fee and no change output was generated. Researchers point out that this fixed fee model distinguishes this attack from ordinary bitcoin collections and points it to a single automated operator. The report showed that the stolen addresses included 1,183 native SegWit addresses, 7 BIP-49 addresses, and 6 BIP-44 addresses. Galaxy Research said this distribution is consistent with automated scanning for multiple wallet derivation paths.
The researchers also found that these transactions did not occur continuously, but occurred in batches. During the 41-minute attack period, there were three spaced blocks where no sweep activity occurred. At the same time, Galaxy Research pointed out that the stolen funds flowed to four Bitcoin addresses and that the funds have not been transferred since the first collection.
Firmware vulnerability triggers emergency response
Coinkite first warned users that the problem involved seeds generated on Coldcard Mk3 devices running firmware version 4.0.1 and higher. Subsequently, the company extended the warning to some Mk4, Mk5 and Coldcard Q firmware versions and issued an emergency firmware update. Coinkite CEO Rodolfo Novak admitted responsibility for the firmware flaw and apologized to users. He said the company's review process failed to detect the issue before release. Novak also suggested that artificial intelligence may help discover such vulnerabilities, and pointed out that with AI-assisted code review, software weaknesses can be identified faster than traditional manual review.
Researchers warn: More attacks may still occur
Galaxy Research said future attacks may still occur if users continue to deposit funds in affected single-signed Coldcard addresses. However, the agency stressed that future attacks may not follow the same on-chain trading pattern. According to Galaxy Research, the recognizable pattern this time points only to the original attacker and cannot detect future theft because subsequent transactions may appear to be no different from legitimate wallet transfers. The agency urges users to transfer funds to trusted custody services or multi-sign self-custody solutions. Coinkite also recommends that users install updated firmware, generate new seeds, test wallets with small transfers, and keep old backups until the migration is complete.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC