YayaNews LogoYaya Financial News
加密货币Neutral$BTC

How bitcoin cold wallets lost $70 million in an attack that never touched the devices

Galaxy Research said weak seed generation let an attacker recreate likely private keys offline, sweep more than 1,000 BTC from nearly 1,200 wallets and continue searching without ever accessing the devices.

Financial news writerUpdated: 8 ViewsSource CoinDesk

YayaNews contributes financial news and market context through the YayaNews editorial workflow.

How bitcoin cold wallets lost $70 million in an attack that never touched the devices
Image Source: CoinDesk

How bitcoin cold wallets lost $70 million in an attack that never touched the devices

Tech

How bitcoin cold wallets lost $70 million in an attack that never touched the devices

Galaxy Research said weak seed generation let an attacker recreate likely private keys offline, sweep more than 1,000 BTC from nearly 1,200 wallets and continue searching without ever accessing the devices.

By

Shaurya Malwa

Aug 1, 2026, 5:55 a.m.

4

min read

Make

preferred on

Share

Share this article

Copy link

X icon

X (Twitter)

LinkedIn

Facebook

Email

Make

preferred on

Bitcoin cold wallet Coldcard. (Coldcard/Coinkite)

Summary

Show

More than 1,000 bitcoin, worth about $70 million, were drained from 1,196 Coldcard wallets in a 41-minute span on July 30, nearly double the loss first reported.

Researchers say a firmware flaw in certain Coldcard hardware wallets made supposedly unguessable seed phrases computationally enumerable, allowing attackers to reconstruct private keys without ever touching the devices.

Security firms warn that more wallets could be hit because owners cannot reliably tell if their seeds were generated on vulnerable firmware, even as investigators trace the attacker through logs from a blockchain data provider.

More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly

double the amount

reported when the theft first surfaced.

Galaxy Research mapped

the full event on

Friday, finding 1,082.65 BTC swept between 01:10 and 01:51 UTC across six blocks, with three intervening blocks containing nothing, which suggests the transactions were broadcast in batches rather than continuously.

The proceeds sit in four addresses and have not moved. Early reporting captured only one of those addresses, which is why the figure has grown.

The size of the attack is much smaller than some of the bigger attacks this year, but the mechanism is what makes this unusually — and why the attack is such a big deal.

Why the Coldcard wallet exploit is a bigger deal than most exploits

Most crypto theft involves getting to something. An exchange is breached, a contract is tricked, a key is phished off a laptop. The defence has always been distance, which is precisely what a hardware wallet sells. Keep the key on a device that never connects to the internet and, theoretically, there is nothing for an attacker to touch.

Most crypto thefts require reaching the key. This one rebuilt it. (Shaurya Malwa/CoinDesk)

When a wallet is created, the device is supposed to pick a number so large and so unpredictable that guessing it is impossible.

That number is the seed, and every address and private key derives from it by fixed public rules. Coldcard's firmware was meant to draw that number from a dedicated hardware randomness generator. An internal build setting told it to skip that generator, and a check in a supporting library tested only whether the setting existed rather than whether it was switched on.

Key generation fell through to a basic software substitute seeded from the chip's serial number and its clock registers. This serial number is fixed factory metadata, and clock values are timing state an attacker can narrow down or measure on a device of their own.

The consequence was that the range of keys the device could ever produce collapsed from unimaginably vast to countable. Security teams found that generation of keys could be determined on the older Mk2 and Mk3 — numbers for different models of Coldcard — but on the Mk4, Q and Mk5, they put the range at roughly four billion possibilities.

Four billion is a large number to a person but a small one to a computer. An attacker generates candidate seeds on their own hardware, derives the addresses each would produce, and checks those addresses against the public blockchain, which anyone can download.

Every step of that runs on the attacker's machine. The victim's device is not involved at any point and could be powered off in a safe on another continent.

Galaxy's breakdown shows the process running. Of the drained wallets, 1,183 used the modern native segwit address format, seven used an older standard and six an older one still. Nobody targets a specific victim across three address formats at once.

That is systematic enumeration, checking each candidate seed against every path it might have produced. The operator can widen the search, refine it and return whenever they choose.

Galaxy warned further waves are likely if owners do not move their funds.

The victims span three address formats, which is what a scanner looks like. (Shaurya Malwa/CoinDesk)

Nor can an owner determine whether they are exposed. There is no test to run against your own wallet that reveals whether your seed sits inside the reproducible range.

Attack might not be fully finished

Coinkite, Coldcard's maker, has warned Mk3 owners and says its newer devices are unaffected, while Block's report places the Mk2, Mk4, Q and Mk5 in scope as well. Until that is resolved, anyone who generated a seed on the affected firmware has to assume the worst rather than verify it.

The attacker did make one mistake, however.

Block's Clay Garrett

said on X

that the operator used a paid account at a “well-known blockchain data provider” to query the source addresses during the sweeps, and that the provider's internal logs matched the suspected workflow with what he called extraordinary specificity, down to the number, timing and sequence of requests.

1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source…

https://t.co/l5McyhhcNn

— Clay Garrett (@clay_garrett)

July 31, 2026

The provider appears to have been supplying ordinary services to requests that gave no indication of their purpose. Block has passed the information to authorities.

Cold storage promises that a key is unguessable. Everyone read it as a promise that a key is unreachable, and the cost of finding and exploiting flaws in the first kind keeps falling.

Anthropic published research on Tuesday showing one of its models halving the security of a candidate post-quantum algorithm in 60 hours, against a design that had survived two years of expert review.

Storing a key safely is now the easier half of the problem.

Latest Crypto News

1

XRP Ledger upgrade brings back features once pulled over critical bugs

2 hours ago

2

Bitcoin holds monthly gain, faces 'choppy' August as 'forced-selling' exhausted, analysts say

11 hours ago

3

Tether posts $1.5 billion operating profit in Q2 as reserve buffer falls by half

14 hours ago

4

The good and the bad of perps, according to crypto traders

14 hours ago

5

Coldcard's $38 million (so far) exploit shakes faith in self-custody, may push investors to ETFs

15 hours ago

6

Quantum computing nears commercial breakthrough, IBM CEO says

16 hours ago

7

Crypto faces 3 barriers to next bull run, STS Digital CEO says

17 hours ago

8

Circle secures New York trust charter as crypto regulatory push accelerates

19 hours ago

9

Coinbase's weak quarter leaves Wall Street split on timing of a recovery

19 hours ago

10

RWA perps will outpace tokenization

19 hours ago

Latest Research

The Evolution of the Crypto CEX Landscape: A Case Study on Binance

The Evolution of the Crypto CEX Landscape: A Case Study on Binance

Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.

By

CoinDesk Research

Jun 29, 2026

Commissioned by

Binance

Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.

Why it matters

:

Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.

View Full Report

More From

Tech

XRP Ledger upgrade brings back features once pulled over critical bugs

Major bitcoin wallet flaw drains $38 million worth of BTC in 25-minute sweep

The economics behind Aave proposal to ditch 6 chains that earn loose change in revenue

Crypto

CD20

$1,728.84

CD20 down 1.11 percent

1.11%

BTC

$63,041.35

BTC down 1.13 percent

1.13%

ETH

$1,866.78

ETH down 1.14 percent

1.14%

XRP

$1.06

XRP down 1.33 percent

1.33%

SOL

$72.95

SOL down 0.83 percent

0.83%

Disclaimer

Original YayaNews editorial coverage, published for informational purposes.

This article is sourced from CoinDesk. It is for informational purposes only and does not constitute investment advice.

Share

Topics & Symbols

Topics & symbols

Continue Reading

Previous & next

Related Reading

Go to Channel