More than 1,000 bitcoin, worth roughly $70 million, were drained from 1,196 Coldcard hardware wallets in a 41-minute window on July 30, according to Galaxy Research. The attacker swept 1,082.65 BTC between 01:10 and 01:51 UTC across six blocks, with three empty blocks in between, indicating batched transactions rather than continuous sweeps. The stolen funds sit in four addresses and have not moved. Early reporting captured only one address, which is why the total has nearly doubled since initial disclosure. The mechanism is what makes this significant — the attacker never touched the devices.
Researchers found that a firmware flaw in certain Coldcard models caused supposedly unguessable seed phrases to become computationally enumerable. When a wallet is created, the device is meant to draw a random number from a dedicated hardware generator to produce the seed, from which every address and private key derives by fixed public rules. An internal build setting told the firmware to skip that generator, and a check in a supporting library tested only whether the setting existed rather than whether it was switched on. Key generation fell back to a basic software substitute seeded from the chip's serial number and clock registers — fixed factory metadata and timing state an attacker can narrow down or measure on their own device. Security teams found that on the Mk4, Q and Mk5 models, the range collapsed to roughly four billion possibilities. Four billion is a small number to a computer. The attacker generated candidate seeds offline, derived the addresses each would produce, and checked those addresses against the public blockchain — all on their own hardware, with the victim's device never involved and potentially powered off in a safe on another continent.
Galaxy's breakdown shows systematic enumeration. Of the 1,196 drained wallets, 1,183 used the modern native segwit address format, seven used an older standard, and six an older one still. Nobody targets a specific victim across three address formats at once — that is a scanner checking each candidate seed against every path it might have produced. The operator can widen the search, refine it, and return whenever they choose. Galaxy warned further waves are likely if owners do not move their funds. Victims cannot reliably tell if their seeds were generated on vulnerable firmware, and the attacker can continue searching without leaving a trace.
This breaks the hardware wallet trust model that the entire self-custody narrative is built on. The defence has always been distance — keep the key on a device that never connects to the internet, and there is nothing for an attacker to touch. Most crypto thefts require reaching the key. This one rebuilt it. Cold storage was supposed to be the final layer of security, the place where institutional and high-net-worth holders park long-term holdings with confidence. If seed generation can fail silently and predictably, that confidence evaporates. The immediate risk is contained to Coldcard users who generated seeds on affected firmware, but the second-order effect is broader — every hardware wallet vendor now faces scrutiny over their randomness implementation, and every holder using any device is suddenly questioning whether their cold storage is actually cold. That is not a catalyst for new capital to enter crypto, and it is not an environment where risk appetite expands. Funding sits at +0.3 basis points per eight hours, half the 30-day average of +0.6bp, and Fear & Greed registers 27, in line with the 30-day average of 26 — no panic, but no conviction either. The snapshot reflects a market that was already cautious, and this adds a concrete reason to stay that way.
Source: CoinDesk
