Massive Bitcoin Heist Linked to Coldcard Firmware Vulnerability
On July 30, 2026, a coordinated attack drained 1,196 Bitcoin wallets, siphoning 1,082.65 BTC worth approximately $70.2 million in just 41 minutes. The theft, occurring between 01:10:20 and 01:51:26 UTC (blocks 960,183 to 960,191), has been attributed to a suspected vulnerability in Coldcard hardware wallet firmware.
Researchers at Galaxy Research, building on findings from Block engineers and security researcher Clay Garrett, identified the attack as automated, with transactions exhibiting unusual patterns. Nearly all drained wallets (1,183) used SegWit BIP-84 derivation paths, while smaller numbers relied on BIP-49 (7) and legacy BIP-44 (6). This distribution suggests the attacker systematically scanned multiple address formats after gaining access to private keys.
Every compromised wallet was fully emptied, with no change outputs a hallmark of automated theft. Transactions also featured an identical, hardcoded fee rate of 30.0 sat/vB, far exceeding the median network rate of 0.4–1.0 sat/vB at the time. Such overpayment is typical of malware or bulk-draining tools prioritizing speed over cost.
The stolen funds were consolidated into four addresses holding 562.02 BTC, 398.48 BTC, 89.62 BTC, and 32.45 BTC, though no further movement had been detected at the time of reporting. The attack began roughly 30 hours before Coldcard issued a public advisory, raising concerns about delayed vendor response.
While the attacker’s identity remains unconfirmed, the incident underscores risks associated with hardware wallet vulnerabilities and the importance of timely firmware updates.
Source: https://gbhackers.com/coldcard-firmware-flaw/
Coinkite Inc. cybersecurity rating report: https://www.rankiteo.com/company/coinkite
"id": "COI1785738273",
"linkid": "coinkite",
"type": "Vulnerability",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1,196 Bitcoin wallet users',
'industry': 'Cryptocurrency',
'name': 'Coldcard',
'type': 'Hardware Wallet Manufacturer'}],
'attack_vector': 'Firmware Vulnerability',
'customer_advisories': 'Public advisory issued by Coldcard ~30 hours after '
'attack',
'data_breach': {'data_exfiltration': '1,082.65 BTC drained',
'number_of_records_exposed': '1,196 wallets',
'sensitivity_of_data': 'High (cryptographic keys)',
'type_of_data_compromised': 'Bitcoin private keys'},
'date_detected': '2026-07-30T01:10:20Z',
'description': 'On July 30, 2026, a coordinated attack drained 1,196 Bitcoin '
'wallets, siphoning 1,082.65 BTC worth approximately $70.2 '
'million in just 41 minutes. The theft, occurring between '
'01:10:20 and 01:51:26 UTC (blocks 960,183 to 960,191), has '
'been attributed to a suspected vulnerability in Coldcard '
'hardware wallet firmware. Researchers identified the attack '
'as automated, with transactions exhibiting unusual patterns. '
'The stolen funds were consolidated into four addresses, '
'though no further movement had been detected at the time of '
'reporting.',
'impact': {'brand_reputation_impact': 'High (Coldcard hardware wallet brand)',
'data_compromised': '1,082.65 BTC (private keys)',
'financial_loss': '$70.2 million',
'operational_impact': 'Automated wallet draining',
'payment_information_risk': 'High (Bitcoin private keys '
'compromised)',
'systems_affected': '1,196 Bitcoin wallets'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Risks associated with hardware wallet vulnerabilities and '
'the importance of timely firmware updates.',
'motivation': 'Financial Gain',
'post_incident_analysis': {'root_causes': 'Suspected Coldcard hardware wallet '
'firmware vulnerability'},
'recommendations': 'Timely firmware updates, enhanced monitoring of wallet '
'transactions, and systematic scanning for address format '
'vulnerabilities.',
'references': [{'source': 'Galaxy Research'},
{'source': 'Block engineers'},
{'source': 'Security researcher Clay Garrett'}],
'response': {'communication_strategy': 'Public advisory issued ~30 hours '
'after attack',
'third_party_assistance': 'Galaxy Research, Block engineers, '
'security researcher Clay Garrett'},
'title': 'Massive Bitcoin Heist Linked to Coldcard Firmware Vulnerability',
'type': 'Cryptocurrency Theft',
'vulnerability_exploited': 'Coldcard hardware wallet firmware vulnerability'}