Coldcard bug drained $89M in Bitcoin, skewed on-chain signals

Coldcard firmware produced weak seed phrases that let attackers drain 1,367.05 BTC from 4,585 addresses, about $89 million, triggering the largest outflow since FTX.

On July 30, hardware wallet maker Coinkite warned that certain Coldcard firmware generated seed phrases with substantially less randomness than intended, leaving affected wallets vulnerable to theft.

Galaxy Research identified three suspected attack waves that targeted 4,585 addresses and drained 1,367.05 BTC, roughly $89 million. Investigators found the stolen coins remain in attacker-controlled addresses and flagged about 600 addresses believed to hold funds taken from vulnerable devices. Smaller opportunistic thefts were reported moving through peel chains, cross-chain services and offshore casinos.

Coinkite issued corrected firmware for the affected models. The company and analysts noted that updates cannot change seed phrases already generated. Affected holders must create new wallets and transfer balances to secure addresses to regain safe custody.

The migration of funds produced a noticeable surge in on-chain activity. Transactions involving outputs smaller than 1 BTC totaled 39,600 BTC on July 31, the largest daily amount for that cohort since November 2022. Daily active Bitcoin addresses rose from about 645,000 on July 30 to nearly 1 million the next day, the highest level since December 10, 2024. Exchange deposits of transfers below 10 BTC climbed to 7,300 BTC.

Analytics also recorded movement of 77,402 BTC from older unspent-transaction-output bands after the vulnerability became public. Analysts warned that such flows can distort metrics used to track long-term holder behavior and age-based spending charts.

JA Maartunn cautioned: “The Coldcard seed phrase issue may cause old coins to move as users secure their savings. That can distort LTH Supply Change, Coin Days Destroyed, Spent Output Age Bands and other related charts.”

Tracing and freezing the stolen funds became time-sensitive because coins can pass through bridges, exchanges and gambling platforms within minutes. Galaxy Research collected victim reports, clustered suspected attacker addresses and shared findings with law enforcement and compliance investigators.

Teams reported that safety filters on some commercial large language models blocked forensic prompts during tracing, limiting certain automated analyses. Investigators used an open-source, locally hosted model to continue work where commercial models refused inputs. Providers, security teams and investigators are balancing the need for rapid forensic capabilities with controls that prevent misuse of the same tools.

Investigations and recovery efforts are ongoing, with firms and authorities monitoring suspicious flows to identify points where coins can be frozen or reclaimed.

Articles by this author