A software vulnerability in Coldcard hardware wallets has resulted in the theft of roughly 1,082 Bitcoin — worth approximately $70 million at current prices — according to new analysis from Galaxy Research cited by Cointelegraph, CoinDesk, and The Block. The breach has become one of the most significant self-custody security failures in Bitcoin's history.
What Actually Happened
The attack did not require physical access to any device. Galaxy Research identified 1,196 addresses drained over a 41-minute window, all tied to a flaw in how Coldcard generated seed phrases. The randomness — technically called entropy — used to create private keys was weak enough that an attacker could recreate likely private keys entirely offline, then sweep funds without the wallet owner knowing anything was wrong. According to CoinDesk, the attacker is still searching for additional vulnerable wallets.
Bitcoin Magazine reported that AI-assisted tools may have been used both to discover the latent bug and potentially to accelerate the attack. Coinkite, Coldcard's manufacturer, has since confirmed the vulnerability and released a fixed firmware update. Experts quoted by Bitcoin Magazine have urged all Coldcard users to move funds to a newly generated wallet immediately — not just update the firmware, but generate fresh keys on a clean device.
A Blockchain Services Provider May Be Involved
A separate report from Bitcoin Magazine noted that investigators believe the attacker may have used a major blockchain data services provider to identify and target vulnerable addresses at scale. That detail, if confirmed, would suggest a more sophisticated and coordinated operation than a lone opportunist scanning the network.
What This Means for Self-Custody
CoinDesk noted that the incident is already prompting some investors to reconsider whether managing private keys is too technically demanding for everyday holders. Spot Bitcoin ETFs, by contrast, attracted $172.4 million in July inflows according to Cointelegraph — a modest positive month, though still deeply negative year-to-date after heavy outflows in May and June.
That comparison deserves careful framing. ETFs carry their own risks: custodial counterparty exposure, management fees, and no ability to transact directly. Self-custody, when implemented correctly with properly generated keys and secure backups, remains the standard that Bitcoin was designed around. This incident was a manufacturing-level software flaw, not a flaw in the concept of self-custody itself.
Key Takeaways
- Affected users: Anyone who generated a wallet on a vulnerable Coldcard firmware version should treat those keys as compromised and move funds now.
- The fix: Coinkite has released updated firmware. New seed generation after updating produces secure entropy.
- Scope may grow: Galaxy Research says the attacker is still active, meaning the $70 million figure could rise.
- Regulatory signal: Incidents like this give ammunition to lawmakers pushing for custodial and device security standards in the pending Clarity Act, which Coinbase's chief policy officer told The Hill this week has genuine bipartisan support.
Bitcoin's price closed July around $63,035, holding a monthly gain despite the security news and broader macro uncertainty, according to CoinDesk. Analysts described August as likely choppy, with rate decisions and jobs data ahead.
For anyone donating Bitcoin to charity, this is a timely reminder to verify your wallet's firmware and ensure your seed phrase was generated on a device you trust. Sound custody practices protect your ability to give.