Coldcard hardware wallet theft estimate nearly doubles to $70m, testing custody assurances
Galaxy Research says a Coldcard firmware flaw let attackers drain 1,082 BTC from 1,196 wallets, reviving scrutiny of self-custody security claims.

The scale of a security failure affecting Coinkite’s Coldcard hardware wallet has nearly doubled, with Galaxy Research now estimating that 1,082.65 bitcoin, worth roughly $70 million, was drained from 1,196 wallets in a single 40-minute window. The revised figure, published on Friday, replaces an initial estimate of 594 BTC (around $38 million) taken from approximately 500 single-signature wallets, underscoring how quickly the scope of on-chain forensic investigations can shift once independent researchers gain access to the same data.
Galaxy’s analysis puts the bulk of the withdrawals between 01:10 and 01:50 UTC on 30 July. Each affected address held more than 0.15 BTC, and more than 562 BTC was ultimately consolidated into a single address that has not since moved the funds, according to the research firm. The episode has quickly become one of the largest known losses tied to a single hardware wallet vulnerability, and it sits awkwardly alongside the industry’s broader pitch that self-custody devices offer superior protection to exchange-held assets.
A flaw traced to weak randomness
Coldcard devices are designed as air-gapped hardware wallets that generate a 24-word mnemonic seed phrase intended to be cryptographically unpredictable. According to a report from Block’s engineering and security teams, the firmware contained two separate random-number-generation functions sharing an identical cryptographic signature: a hardware implementation written by Coinkite and a software fallback inherited from MicroPython.
A build-time check meant to confirm which version was active failed to trigger correctly, meaning some devices ended up relying on the weaker software generator, which drew on the processor’s serial number and internal clock — inputs that are not considered cryptographically secure. The vulnerability affected firmware versions 4.0.0 to 4.2.0, spanning the initial release from March 2021 through to the recent patch in version 4.21, meaning any seed generated across that four-year period could theoretically be at risk.
Coinkite’s advisory, updated after the initial Mk3-focused warning, now says all existing Coldcard devices — including Mk3, Mk4, Mk5 and Coldcard Q models — are potentially vulnerable, and that firmware upgrades alone provide only partial protection. The company noted the flaw also compromises other features relying on the same randomness function, including paper wallet encryption, key-splitting tools, mask generation and the Key Teleport feature.
Coinkite accepts responsibility, points to AI
Coinkite chief executive Rodolfo Novak issued a public apology, stating: “We took full accountability for the firmware bug that led to this situation.” He acknowledged that the company’s original code review process had failed to catch the underlying issue before it reached production devices.
Novak also suggested the attacker may have used artificial intelligence tools to identify the flaw, describing the episode as “a sobering reminder of the new paradigm we are entering with AI.” Both reports on the incident note this framing sits somewhat uneasily given that Coinkite has itself previously used AI-assisted tools to scan its own codebase for vulnerabilities.
Coinkite has urged all users who generated seeds under the affected firmware to update to the patched version, generate a new wallet, and migrate funds only after independently verifying the new receiving address. Block’s researchers cautioned that the on-chain trail identifying the thief’s wallet, previously flagged by other analysts including Clay Garrett, does not itself reveal the underlying vulnerability, warning that “future attacks could target any Coldcard address generated using the vulnerable firmware.”
For institutional custodians and retail holders alike, the widening loss estimate raises fresh questions about the assurance standards applied to hardware wallet firmware, and whether third-party audit and disclosure practices across the sector are keeping pace with the scale of assets now held in self-custody.
Read more: Coinkite warns Coldcard Mk3 users of seed flaw as 594 BTC theft reports surface


