Nearly 1,200 Bitcoin addresses were emptied of a combined 1,082.65 BTC, valued at about $70.2 million, in a 41-minute sweep on July 30 that Galaxy Research linked to a seed-generation vulnerability in certain Coldcard hardware wallets. The incident followed an emergency warning from Coldcard maker Coinkite that some devices may have created wallet recovery seeds vulnerable to guessing.
Galaxy Research said 1,196 addresses were drained in full between 01:10:20 and 01:51:26 UTC on July 30. The research firm traced the transactions using a pattern first identified by engineers at Block and shared by security researcher Clay Garrett.
The speed and breadth of the withdrawals point to an automated operation rather than a series of isolated wallet compromises. In its analysis, Galaxy Research said the transactions appeared to have been initiated through a method that could identify and empty wallets whose private keys were derived from affected Coldcard-generated seeds.
Coinkite expands emergency firmware advisory
Coinkite issued its initial warning on Thursday, saying the issue affected seeds generated on Coldcard Mk3 devices running firmware version 4.0.1, released in March 2021, or later versions. The company later broadened the advisory to include certain firmware versions for the Mk4, Mk5 and Coldcard Q devices.
A wallet seed is the sequence of recovery words used to generate a wallet’s private keys. Anyone who obtains or can reproduce that seed can control the Bitcoin held at every address created from it. Coinkite’s warning indicated that a flaw in the affected software could have weakened the randomness used during seed creation, allowing attackers to derive seeds that should have been practically impossible to guess.
The defect concerns seed generation rather than a physical breach of a device. Hardware wallets are designed to keep private keys offline, but their protection depends on the seed being generated with sufficient entropy, or unpredictability. If the original seed can be recreated by an outside party, the attacker can sign a valid on-chain transfer without possessing the wallet itself.
Coinkite released emergency firmware updates for the affected models and advised users who generated a seed on potentially vulnerable software to move funds to a newly created wallet seed after updating their device.
Company chief accepts responsibility
Rodolfo Novak, Coinkite’s chief executive officer, apologized on Friday and said the company accepted full accountability for the firmware bug. Novak also said artificial intelligence may have helped attackers identify the flaw and conduct the rapid wallet sweeps, describing the incident as part of a “new AI paradigm.”
The available transaction data does not establish who carried out the thefts or whether AI tools were used. Yet the concentration of withdrawals within a narrow period suggests that the party behind them had a scalable way to identify addresses associated with vulnerable seeds and broadcast transactions in rapid succession.
Galaxy Research said the July 30 activity was not necessarily the full extent of the losses connected to the pattern. Its timeline cited 695 earlier transactions that moved another 488 BTC under the same identified behavior. The researchers cautioned that any address created with an affected Coldcard seed could remain exposed until its funds are moved.
That warning is particularly consequential for users who may have generated a wallet years ago and kept Bitcoin in long-term storage without regularly checking firmware notices. Updating the firmware alone would not protect funds tied to an already compromised or predictable seed. A new seed and a transfer of the balance are required to separate the funds from the old wallet’s key material.
On-chain transfers can resemble ordinary withdrawals
Galaxy Research said a future attack against affected wallets could use methods that do not match the pattern observed in the July 30 sweep. On the Bitcoin blockchain, a transaction signed with a valid private key looks the same whether it was created by the rightful wallet owner or by someone who gained access to the seed.
That makes detection difficult for individual holders. A transaction may carry no obvious on-chain marker identifying it as theft, and a hardware wallet’s offline design cannot stop a transfer once an attacker has independently reconstructed the necessary private key.
The episode also differs from the more familiar hardware-wallet risks involving phishing, fraudulent software downloads or users revealing recovery words. Coinkite’s advisory centers on the wallet’s own seed-generation process during certain firmware periods. Users who never shared their backup phrase could nevertheless be exposed if the affected firmware produced insufficiently random seeds.
Steps recommended for affected users
Coinkite told potentially affected customers to install the latest firmware, create a completely new seed, and move their Bitcoin to addresses derived from that new seed. The company advised testing the process with a small transaction before transferring a full balance, reducing the chance that an error in setup or address verification results in a separate loss.
Users should retain the old recovery backup until they have confirmed that every asset has arrived in the new wallet. Destroying or discarding the old backup before the transfer is complete could make it harder to recover funds if a transaction is sent incorrectly or a wallet configuration problem arises.
The incident puts pressure on hardware-wallet makers to treat random-number generation and seed creation as security-critical components subject to intensive review. A secure chip, an offline signing process and physical confirmation screens offer limited protection if the wallet begins with recovery words that an attacker can reproduce.
For Coldcard users, the immediate practical question is whether their wallet seed was generated on firmware covered by Coinkite’s advisory. Those users face a more urgent task than a routine software update: replacing the seed that controls their Bitcoin before another party can use the same underlying weakness to move the funds.
Worried about wallet hacks? Learn key protection steps in this security guide to safeguard your crypto holdings.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

