toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trade
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
Be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android version app
More download options

Coldcard vulnerability drains 1082 Bitcoin from wallets

2026-07-31 20:41

Nearly 1,200 Bitcoin addresses were emptied of a combined 1,082.65 BTC, valued at about $70.2 million, in a 41-minute sweep on July 30 that Galaxy Research linked to a seed-generation vulnerability in certain Coldcard hardware wallets. The incident followed an emergency warning from Coldcard maker Coinkite that some devices may have created wallet recovery seeds vulnerable to guessing.

Galaxy Research said 1,196 addresses were drained in full between 01:10:20 and 01:51:26 UTC on July 30. The research firm traced the transactions using a pattern first identified by engineers at Block and shared by security researcher Clay Garrett.

The speed and breadth of the withdrawals point to an automated operation rather than a series of isolated wallet compromises. In its analysis, Galaxy Research said the transactions appeared to have been initiated through a method that could identify and empty wallets whose private keys were derived from affected Coldcard-generated seeds.

Coinkite expands emergency firmware advisory

Coinkite issued its initial warning on Thursday, saying the issue affected seeds generated on Coldcard Mk3 devices running firmware version 4.0.1, released in March 2021, or later versions. The company later broadened the advisory to include certain firmware versions for the Mk4, Mk5 and Coldcard Q devices.

A wallet seed is the sequence of recovery words used to generate a wallet’s private keys. Anyone who obtains or can reproduce that seed can control the Bitcoin held at every address created from it. Coinkite’s warning indicated that a flaw in the affected software could have weakened the randomness used during seed creation, allowing attackers to derive seeds that should have been practically impossible to guess.

The defect concerns seed generation rather than a physical breach of a device. Hardware wallets are designed to keep private keys offline, but their protection depends on the seed being generated with sufficient entropy, or unpredictability. If the original seed can be recreated by an outside party, the attacker can sign a valid on-chain transfer without possessing the wallet itself.

Coinkite released emergency firmware updates for the affected models and advised users who generated a seed on potentially vulnerable software to move funds to a newly created wallet seed after updating their device.

Company chief accepts responsibility

Rodolfo Novak, Coinkite’s chief executive officer, apologized on Friday and said the company accepted full accountability for the firmware bug. Novak also said artificial intelligence may have helped attackers identify the flaw and conduct the rapid wallet sweeps, describing the incident as part of a “new AI paradigm.”

The available transaction data does not establish who carried out the thefts or whether AI tools were used. Yet the concentration of withdrawals within a narrow period suggests that the party behind them had a scalable way to identify addresses associated with vulnerable seeds and broadcast transactions in rapid succession.

Galaxy Research said the July 30 activity was not necessarily the full extent of the losses connected to the pattern. Its timeline cited 695 earlier transactions that moved another 488 BTC under the same identified behavior. The researchers cautioned that any address created with an affected Coldcard seed could remain exposed until its funds are moved.

That warning is particularly consequential for users who may have generated a wallet years ago and kept Bitcoin in long-term storage without regularly checking firmware notices. Updating the firmware alone would not protect funds tied to an already compromised or predictable seed. A new seed and a transfer of the balance are required to separate the funds from the old wallet’s key material.

On-chain transfers can resemble ordinary withdrawals

Galaxy Research said a future attack against affected wallets could use methods that do not match the pattern observed in the July 30 sweep. On the Bitcoin blockchain, a transaction signed with a valid private key looks the same whether it was created by the rightful wallet owner or by someone who gained access to the seed.

That makes detection difficult for individual holders. A transaction may carry no obvious on-chain marker identifying it as theft, and a hardware wallet’s offline design cannot stop a transfer once an attacker has independently reconstructed the necessary private key.

The episode also differs from the more familiar hardware-wallet risks involving phishing, fraudulent software downloads or users revealing recovery words. Coinkite’s advisory centers on the wallet’s own seed-generation process during certain firmware periods. Users who never shared their backup phrase could nevertheless be exposed if the affected firmware produced insufficiently random seeds.

Steps recommended for affected users

Coinkite told potentially affected customers to install the latest firmware, create a completely new seed, and move their Bitcoin to addresses derived from that new seed. The company advised testing the process with a small transaction before transferring a full balance, reducing the chance that an error in setup or address verification results in a separate loss.

Users should retain the old recovery backup until they have confirmed that every asset has arrived in the new wallet. Destroying or discarding the old backup before the transfer is complete could make it harder to recover funds if a transaction is sent incorrectly or a wallet configuration problem arises.

The incident puts pressure on hardware-wallet makers to treat random-number generation and seed creation as security-critical components subject to intensive review. A secure chip, an offline signing process and physical confirmation screens offer limited protection if the wallet begins with recovery words that an attacker can reproduce.

For Coldcard users, the immediate practical question is whether their wallet seed was generated on firmware covered by Coinkite’s advisory. Those users face a more urgent task than a routine software update: replacing the seed that controls their Bitcoin before another party can use the same underlying weakness to move the funds.


Worried about wallet hacks? Learn key protection steps in this security guide to safeguard your crypto holdings.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trade
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.