The scale of the Coldcard hardware wallet exploit has grown significantly, with Galaxy Research now estimating that 1,082.65 BTC — worth roughly $70.2 million — was drained from 1,196 addresses in a single 41-minute window on July 30. The new figure nearly doubles an earlier estimate from AnchorWatch CEO Rob Hamilton, who had initially flagged 594.48 BTC (about $38 million) stolen across 500 transactions in a three-block span.
Galaxy's expanded analysis traced the theft to blocks 960,183 through 960,191, with the drain beginning at 1:10 AM UTC and concluding by 1:51 AM UTC on July 30.
A consistent attacker fingerprint
Researchers identified a distinctive pattern across the affected transactions: every sweep used a uniform fee of 30 satoshis per virtual byte and included no change outputs, suggesting a single automated operation rather than opportunistic, unrelated attackers. Galaxy cautioned, however, that this signature may not hold for future incidents, noting that "future attacks against Coldcard-generated addresses may not follow the same fingerprint."
Coinkite's response
Coinkite co-founder Rodolfo Novak acknowledged the flaw, saying the company "takes responsibility for the firmware bug." He urged any user who generated a seed on vulnerable firmware to move funds to a freshly generated seed rather than simply applying the patch, since a firmware update alone cannot retroactively secure keys that were already generated insecurely. Coinkite has since released a hotfix that removes the vulnerable software fallback path from seed generation.
Why the estimate keeps climbing
The widening gap between the original $38 million estimate and Galaxy's $70.2 million figure reflects how quickly on-chain forensics can reshape the understood scope of a wallet-level exploit. With a security advisory published roughly 30 hours after the attack, some affected holders may not have moved funds before Galaxy's fuller accounting emerged on August 1 — underscoring the urgency of Coinkite's advice to migrate to new, hotfixed seeds rather than treat the firmware update alone as sufficient protection.