Coldcard Exploit: Who Lost Bitcoin and Who’s at Risk

An attacker exploited weak seed generation in certain Coldcard hardware wallets to steal bitcoin from hundreds of addresses on July 30, in a tightly coordinated operation that lasted roughly 25 minutes. Galaxy Research’s on-chain analysis estimates losses in the tens of millions of dollars and links approximately 1,196 addresses to the incident.

What Happened

According to Galaxy Research, the theft centered on vulnerabilities in how some devices generated seed phrases — the core secrets used to derive private keys and sign transactions. If a seed is produced with insufficient randomness, an adversary can potentially reconstruct it and seize control of associated funds.

Investigators say the main wave of thefts occurred in a brief, synchronized burst, suggesting the attacker had precomputed or identified a set of weak seeds in advance. Funds were then swept from targeted addresses in quick succession.

Scale and Impact

  • Losses: Estimated in the tens of millions of dollars in bitcoin, based on prevailing market prices at the time.
  • Duration: Primary consolidation activity occurred over roughly 25 minutes on July 30.
  • Scope: Hundreds of addresses were directly drained; a broader clustering analysis linked about 1,196 addresses to the attack activity.

The incident underscores systemic risks that arise when wallet seed generation lacks adequate entropy, even on devices designed to isolate private keys from internet-connected systems.

Who May Be at Risk

Users whose bitcoin wallets were initialized with seed phrases generated by affected Coldcard devices could be vulnerable, even if their funds have not yet moved. The precise set of models or firmware versions implicated has not been independently verified in this report. Users uncertain about their seed’s provenance should assume caution until more detailed technical guidance is available from security researchers and the manufacturer.

Ongoing Response and User Actions

On-chain analysts continue to track the attacker’s consolidation patterns and related addresses. In general, security practitioners recommend that users who suspect they may be affected:

  • Move funds to a new wallet created with a freshly generated seed on a trusted, up-to-date device.
  • Verify firmware authenticity and integrity before initializing any hardware wallet.
  • Avoid reusing potentially compromised seed phrases.
  • Monitor known exposed addresses for unusual activity.

Galaxy Research’s findings highlight the importance of robust, verifiable randomness in wallet initialization. Further disclosures from independent researchers and the device manufacturer are expected to clarify the specific conditions that led to weak seed generation and the full scope of exposure.

×