The financial toll from a critical flaw in Coldcard hardware wallets has nearly doubled from initial estimates, with Galaxy Research now putting total losses at 1,082.65 BTC — roughly $70.2 million — drained from 1,196 addresses. The theft unfolded in a striking 41-minute window on July 30, prompting Binance founder Changpeng Zhao to issue a public reminder that no storage method is entirely safe.

Zhao, widely known as CZ, posted on X urging holders to spread their funds across multiple wallets rather than concentrating them in a single device.

Nothing is 100%

he wrote, acknowledging that even well-established hardware wallets can carry undiscovered bugs and that no setup is truly foolproof.

a laptop computer sitting on top of a white table
Photo by Hendrik Morkel on Unsplash

How the Flaw Originated

The root cause traces back to a March 2021 firmware build error at Coinkite, the manufacturer of Coldcard devices. Affected units generated private key seeds from a software fallback instead of relying on the device's dedicated hardware random-number generator, making the resulting keys significantly more predictable and, ultimately, crackable by attackers who understood the weakness.

Initial Estimates Fell Far Short

When the exploit first came to light, researchers pegged the damage at roughly 594 BTC, or about $38 million, spread across some 500 wallets. Galaxy Research's updated tally more than doubled both the bitcoin amount and the number of affected addresses, indicating the vulnerability had a far wider blast radius than first understood.

Forensic Fingerprints of the Attack

Galaxy Research identified the coordinated theft through several distinctive on-chain patterns: identical hardcoded transaction fees across every withdrawal, an absence of change outputs, and systematic scanning across multiple key derivation paths that covered both newer SegWit addresses and older address formats. The stolen bitcoin was consolidated within minutes of being swept but has remained stationary since, suggesting the attacker may be waiting before moving or cashing out the funds.

Coinkite's Response

Coinkite has released emergency firmware patches and is urging any customer who might be running an affected build to migrate their funds to freshly generated seeds as soon as possible. The episode adds to a string of high-profile hardware and software wallet vulnerabilities that have periodically rattled confidence in self-custody tools, even as the sector continues to promote them as the safest way to hold bitcoin long term.