Bitcoin (BTC) Coldcard Hack Drains $70M From 1,196 Wallets
BTC/USDT
$16,177,256,782.15
$64,657.27 / $62,466.00
Change: $2,191.27 (3.51%)
+0.0026%
Longs pay
AI SummaryAI
- Attackers drained 1,082.65 BTC from 1,196 Coldcard-linked addresses in a 40-minute window on July 30.
- Coinkite’s advisory covered Coldcard Mk3 seed phrases generated on firmware 4.0.1 through 5.0.3.
- The sweeps used a uniform 30 sat/vB fee and produced no change outputs, according to on-chain data.
- Block engineer Clay Garrett said the operator used a paid blockchain-services account and authorities were notified.
This summary was AI-generated, AI-reviewed and published under COINOTAG editorial oversight.
Bitcoin News
A firmware flaw in Coldcard devices led to the loss of more than $70 million in Bitcoin (BTC) after attackers drained 1,082.65 BTC from 1,196 addresses, according to on-chain analysis of the transfers. The transfers were concentrated in a 40-minute window early on July 30, and each affected address held more than 0.15 BTC. The revised tally dwarfs an initial estimate of 594 BTC taken from about 500 single-signature wallets. Block’s engineering and security teams identified a common transaction pattern and warned that any Coldcard address generated with the vulnerable firmware could remain exposed. Coinkite later said the bug affected seed generation going back to firmware 4.0.0 from March 2021, while urging users to move funds to newly created wallets. The company’s chief executive, Rodolfo Novak, apologized and said the firm took responsibility for the mnemonic-generation error. Bitcoin market reaction was muted, but the incident raises fresh questions about hardware wallet assurance.
Coinkite’s public advisory focused first on Coldcard Mk3 units that created seed phrases while running firmware 4.0.1 through 5.0.3, telling users to treat every associated address as compromised. The company recommended generating a new seed on updated hardware, sending small test transactions, and only then migrating larger balances. On-chain data showed the sweeps used a uniform 30 sat/vB fee and produced no change outputs, signs that an automated script resembling an AI Trading Bot controlled the private keys rather than individual owners acting manually. The stolen coins were consolidated into four addresses, and no outward movement had been observed at the time of review. The timing is sensitive because the transfers began roughly 30 hours before Coinkite disclosed the vulnerability publicly. Security researchers have stressed that replacing a device alone is insufficient if the old seed is imported again, because the weakness lies in the original entropy used to create the phrase. Users should verify receive addresses carefully to avoid rushed mistakes.
Investigators traced the operation through an unusual blockchain-services footprint. Block engineer Clay Garrett said the team identified a pattern in the sweeps and confirmed that the operator used a paid account at a major blockchain-services provider to query source addresses and carry out related activity during the drains. Garrett said authorities had been notified, though the provider was not named at its request. The same on-chain pattern indicated a single attacker, even though individual transactions could resemble ordinary owner transfers. Coinkite initially linked the problem to Coldcard Mk3 devices, where seed generation fell back to a weak software pseudorandom number generator instead of the intended hardware entropy source. That made private keys predictable enough to brute-force, particularly for wallets created without dice rolls or a strong BIP-39 passphrase. After additional thefts, Coinkite acknowledged that all existing device lines could be exposed, and engineers warned that more addresses might remain at risk.
Earlier blockchain records reviewed by researchers showed about 594.48 BTC leaving roughly 500 single-signature addresses across three blocks, from height 960188 to 960191, before being consolidated. AnchorWatch co-founder Rob Hamilton counted 1,324 UTXOs in the sweep and noted that about 562 BTC moved to a fresh address. A later review by Garrett found 695 older transactions with the same fingerprint, involving another 488.11 BTC, pushing the combined tally toward the 1,082.65 BTC figure cited by later on-chain analysis. Bitcoin core developer James O’Beirne urged users who generated single-key wallets on Mk3 devices between 2021 and 2023, without dice entropy, a BIP-39 passphrase, or multisig, to move funds immediately. Wizardsardine chief executive Kevin Loaec speculated that a low-quality random number generator could have allowed AI-assisted brute-force tools to search a narrowed key range, but he stressed that this remains unproven. It also renewed scrutiny of AI Crypto Wallet security assumptions. Coinkite has advised new seeds, test transfers, and, for advanced users, dice-based seed creation. The company has not published full technical details of the root cause.
COINOTAG's proprietary 42-indicator composite S/R scoring engine shows Bitcoin (BTC) trading near $62,976 after a 3.24% daily decline, with the $62,704 support rated 79/100 by S3, Bollinger Lower, Donchian Lower, and Swing Low confluence. The nearest resistance at $63,886 scores 76/100, driven by Flip S→R, Ichimoku Kijun, and EMA 20, making a breakout attempt difficult while RSI sits at 44.38 and MACD remains bearish. Derivatives positioning is crowded long: funding is 0.0022%, open interest is $12.7 billion, and the long/short account ratio is 2.37. With Fear and Greed at 25, a bear market fear reading could fuel a squeeze above $63,886, but losing $62,704 would validate the downtrend and open the $61,411 support.
COINOTAG does not provide financial advisory services. This content is for informational purposes only and should not be considered investment advice. Cryptocurrency investments involve high risk.
Add COINOTAG as a Preferred Source
Add COINOTAG to your preferred sources in Google News and Search to see our coverage first.
Add on GoogleRelated Tags
AI-generated, AI-reviewed, under COINOTAG editorial oversight.


