Galaxy Research Expands Coldcard Wallet Loss to 1,082.65 BTC, Highlighting Firmware Bug Impact
Galaxy Research’s expanded mapping reveals a broader scope than earlier estimates. AnchorWatch CEO Rob Hamilton had previously calculated that 594.48 BTC—worth about $38 million—moved across 500 transactions within a three‑block window. The new analysis identifies a larger set of transactions that share a common pattern, indicating that the breach was more extensive than initially reported.
The distinct transaction signature uncovered by Galaxy Research—identical fees of 30 satoshis per virtual byte and the absence of change outputs—provides a clear fingerprint for the early attack. While this pattern helps isolate the July 30 sweep, the firm cautions that future attacks on Coldcard‑generated addresses may not follow the same signature.
Coinkite, the developer of the Coldcard hardware wallet, has acknowledged responsibility for the firmware bug that enabled the loss. Coinkite co‑founder Rodolfo Novak posted on X that the company is working to determine the full scope of the issue and has released a hotfix that removes the firmware fallback path. However, the update does not protect seeds that were generated on vulnerable firmware versions.
The firmware flaw weakened seed‑generation entropy on specific older devices, exposing some Coldcard wallets to compromise. The bug was introduced in firmware version 4.0.1, released in March 2021. Every seed generated on an affected Coldcard between that date and the patched releases on July 31 2026 is potentially compromised, according to Coinkite’s statements.
Coinkite issued an emergency hotfix—version 5.6.0 for Mk4 and Mk5 devices and 1.5.0Q for the Q. Updating to these versions removes the fallback path that allowed the entropy weakness, but it does not retroactively secure wallets that were created during the vulnerable period. The company advises users who created seeds on affected firmware to move their funds to a new seed as a precaution.
The incident underscores the importance of secure seed generation in hardware wallets. While the hotfix addresses the immediate vulnerability, it cannot repair a seed already created on the affected firmware. Users with Coldcard Mk3, Mk4, Mk5, or Q devices are urged to verify whether their firmware is up to date and to consider moving funds to a new seed if they used an older firmware version.
Galaxy Research’s mapping provides a more complete picture of the Coldcard loss and illustrates how on‑chain analysis can uncover the scale of a hardware wallet breach. The expanded figure of 1,082.65 BTC underscores the potential impact of firmware bugs on the broader Bitcoin ecosystem and reinforces the need for rigorous security practices in wallet development and user education.
At present, no regulatory action or court proceedings have been announced in relation to the incident. The incident has not triggered a protocol upgrade or a change to Bitcoin’s core software. The focus remains on user protection and on ensuring that firmware updates are applied promptly to mitigate future risks.
Galaxy Research will continue to monitor the blockchain for additional activity related to the Coldcard incident. Coinkite has stated that it will assess the full scope of the bug and provide further guidance to users. The incident serves as a reminder that even well‑established hardware wallets can be vulnerable to firmware errors, and that users must remain vigilant about firmware updates and seed management.