A calculator, tweezers, and a precision tool on a
Crypto

Galaxy Research links Coldcard incident to 1,082.65 BTC across 1,196 addresses

Coinkite says a hotfix won’t secure already-generated vulnerable seeds, urging users to migrate funds.

By Emma Carter9 min read

Galaxy Research expanded the estimated scope of the Coldcard hardware wallet incident to 1,082.65 BTC, tied to 1,196 addresses and valued at about $70.2 million at the time of the transactions. Coinkite acknowledged a firmware bug and warned that a newly shipped hotfix does not protect seeds generated on vulnerable firmware, pushing affected users toward immediate fund migration.

Key Takeaways

  • Galaxy Research clustered 1,196 Bitcoin addresses tied to the Coldcard incident and attributed 1,082.65 BTC in losses, valued at about $70.2 million at the time.
  • The incident-linked movements were concentrated in a 41-minute burst on July 30 from 1:10 to 1:51 UTC, spanning Bitcoin blocks 960,183 through 960,191.
  • The identified transactions shared an on-chain fingerprint of 30 sat/vB fees and no change outputs, though Galaxy cautioned future attacks may not preserve the same pattern.
  • Coinkite co-founder Rodolfo Novak said the firm “takes responsibility for the firmware bug,” shipped a hotfix “to remove the software fallback path,” and warned it “does not protect seeds generated on vulnerable firmware.”

Galaxy’s Map Pushes the Coldcard Loss Estimate to 1,082.65 BTC

Galaxy Research, the research arm of Galaxy Digital, put a much larger number on the Coldcard incident than the market had been working with: 1,082.65 BTC linked to 1,196 addresses, worth about $70.2 million at the time of the transactions. For traders, the number matters less as a headline and more as a signal that the incident is not confined to a small, easily enumerated set of victims, because clustering at this scale tends to be the point where “a few compromised wallets” becomes “an ecosystem problem” for self-custody narratives.

The new estimate also reframes earlier public sizing. AnchorWatch CEO and co-founder Rob Hamilton had previously offered a preliminary estimate of 594.48 BTC, worth around $38 million, moving across 500 transactions within a three-block window. Galaxy’s mapping materially increases both the BTC total and the implied breadth of affected addresses, which is usually what changes user behavior, because it suggests the first visible wave was not the full boundary of exposure.

What stands out in Galaxy’s work is that it is not just a bigger number. It is a bigger number paired with a clustering method that can be repeated by other analysts, at least for the initial activity set. That is the kind of detail that tends to accelerate follow-on attribution work and, in parallel, accelerates user migration decisions when the vendor response includes any caveat about already-generated keys.

Inside the 41-Minute Drain: Blocks 960,183–960,191 and a Repeatable Transaction Pattern

Galaxy traced the incident-linked Bitcoin movements to a tight window on July 30, running from 1:10 AM to 1:51 AM UTC and spanning blocks 960,183 to 960,191. The compression matters. A 41-minute sweep reads like coordinated execution rather than slow leakage, and it also means the on-chain footprint is likely dominated by the attacker’s operational choices, not by victims reacting over hours or days.

Galaxy also described a specific on-chain fingerprint across the identified transactions: identical fees of 30 satoshis per virtual byte (sat/vB) and no change outputs. sat/vB is the fee-rate unit used to compare Bitcoin transaction fees by size, and a change output is the “leftover” output that returns unspent funds back to the sender when inputs exceed the amount being paid. No change outputs can be a tell, because it implies the transaction was constructed to spend inputs cleanly without returning excess to the originating wallet.

That fingerprint is useful for retrospective clustering because it gives investigators a concrete filter to find related transactions, and it helps explain how Galaxy expanded the address set. The catch is Galaxy’s own warning: future attacks against Coldcard-generated addresses may not follow the same pattern. In practice, that means the absence of new matches to the 30 sat/vB and no-change-output template is weak reassurance, because an adaptive attacker can vary fee rates, add change outputs, or otherwise break the pattern without changing the underlying exploit path.

The timeline also places the on-chain activity about 30 hours before Coldcard published its first security advisory. That gap is not unusual in incident response, but it is the kind of procedural detail that self-custody users remember, because it defines how much time an attacker had to operate before the vendor’s first public guidance landed.

Coinkite’s Hotfix and the Critical Caveat: Vulnerable Seeds Stay Vulnerable

Coinkite’s response, as framed by co-founder Rodolfo Novak, is unusually direct on responsibility and unusually sharp on what the fix does not do. Novak said the company “takes responsibility for the firmware bug” and is working to determine the full scope of the issue.

The remediation step is a hotfix, described as released “to remove the software fallback path.” A hotfix is a rapid update meant to address a critical bug or security issue, and removing a fallback path is typically a containment move, the kind of change that closes an unintended route through the code that should not have been reachable in the first place.

The critical caveat is Novak’s warning that the update “does not protect seeds generated on vulnerable firmware.” A seed is the recovery phrase that generates a wallet’s private keys, and anyone with it can control the funds. If the risk is tied to how seeds were generated on specific firmware, then patching the device after the fact does not retroactively make those seeds safe.

That is why Novak’s action item is not “update and relax.” He advised users who generated seeds on vulnerable firmware to move their funds to a new seed. In market terms, that guidance is what turns a firmware patch into an urgent migration event, because it implies the primary security boundary is the seed itself, not the current state of the device.

What remains missing in the available material is the operational detail users need to execute that advice cleanly at scale: which firmware versions are considered vulnerable, and how a user can verify whether their seed was generated on an affected version. Until that is specified, the burden shifts to users to assume they might be in-scope, which is exactly how trust shocks propagate beyond the directly affected set.

What to Monitor Next: Scope, Attribution, and Whether the Pattern Reappears

The next practical milestone is version clarity from Coinkite. Novak’s statements draw a bright line around “seeds generated on vulnerable firmware,” but the excerpted material does not specify which firmware versions qualify or how users can verify their seed-generation context. If Coinkite publishes a precise version range and a verification method, it will narrow the population that needs to treat migration as mandatory rather than precautionary.

On-chain, the obvious monitoring path is to watch for new clusters that resemble the initial fingerprint, especially the 30 sat/vB fee-rate and the absence of change outputs. The limitation is structural: Galaxy explicitly cautioned that future attacks may not follow the same fingerprint, so a clean screen on that pattern should not be read as “no ongoing risk.” The more meaningful signal would be either (a) new activity that matches the pattern, confirming repetition, or (b) credible forensic work that ties additional activity to the same root cause even when the transaction construction differs.

Scope is also still live. Galaxy’s 1,196-address set is the largest quantified map in the provided material, but the incident could extend beyond that cluster or beyond the 1:10–1:51 UTC window. Any updates that refine the address set, the BTC total, or the implied USD valuation will matter, because the market tends to reprice “contained incident” versus “expanding incident” narratives quickly, even when the underlying exploit mechanics are not fully public.

Finally, attribution and methodology validation are the quiet drivers here. Galaxy’s clustering is a claim about linkage, and the strongest confirmation would be independent forensic teams reproducing the same cluster boundaries or explaining where they disagree. If the methodology holds up, the 1,082.65 BTC figure becomes a baseline for risk assessment. If it does not, the market is left with a wide range between Hamilton’s preliminary 594.48 BTC estimate and Galaxy’s expanded map.

My Read: This Is a Self-Custody Trust Shock, Not a One-Off On-Chain Oddity

The filing-cabinet detail people are likely to misread is the hotfix itself. A hotfix sounds like closure, and in most software incidents it is, but Novak’s own caveat makes this one different: if the exposure is bound to seeds generated on vulnerable firmware, then the patch is containment for future seed generation, not remediation for past seed generation. That distinction is why the Galaxy clustering matters so much, because it turns a technical bug into a behavioral event where users have to decide whether to rotate to a new seed now, even if they have not seen suspicious activity.

There are two scenarios that matter from here, and they hinge on whether the incident is bounded by the initial 41-minute sweep. If the losses are largely confined to blocks 960,183–960,191, then the market can treat this as a single coordinated drain with a known window, and the main second-order effect is reputational: hardware wallet trust takes a hit, and users overcorrect into migrations, which can create operational mistakes and secondary losses unrelated to the original bug. If, instead, additional losses appear outside that window or outside Galaxy’s 1,196-address cluster, then the story shifts from “attack executed” to “attack capability persists,” and the pressure on Coinkite to publish exact vulnerable firmware versions and verification steps becomes immediate.

The on-chain fingerprint is the other trap. The 30 sat/vB and no-change-output pattern is a good retrospective lens for the first wave, but Galaxy’s warning that future attacks may not match means traders and analysts should not treat “no new matches” as a clean bill of health. The threshold that matters is whether new drains can be linked to Coldcard-generated addresses even when attackers vary fee rates and output structure, because that is what would confirm this is an ongoing exploit surface rather than a single operational sweep.

If Coinkite publishes a tight vulnerable-version range with a reliable way to verify seed provenance, and on-chain activity stays confined to the July 30 window even under broader forensic scrutiny, the incident becomes a contained but expensive trust shock. If scope keeps expanding or new drains appear without the original fingerprint, the core thesis hardens into something more structural: the market is repricing self-custody risk based on seed-generation integrity, not on whether a vendor shipped a patch.

Sources