Galaxy Research Expands Coldcard Bitcoin Theft Estimate to $70 Million

Galaxy Research Expands Coldcard Bitcoin Theft Estimate to $70 Million

Analysis by Galaxy Research uncovered 1,196 wallet addresses affected by the Coldcard security breach, with total losses reaching 1,082.65 Bitcoin during a 41-minute period.

The research division of Galaxy Digital, known as Galaxy Research, has uncovered 1,196 wallet addresses connected to the Coldcard security incident, revealing losses totaling 1,082.65 Bitcoin, which represented approximately $70.2 million in value when the transactions occurred.

According to an X post published on Friday, Galaxy Research monitored the movement of Bitcoin funds during a timeframe spanning from 1:10 AM through 1:51 AM UTC on July 30, covering blockchain blocks numbered 960,183 through 960,191, approximately 30 hours prior to Coldcard's initial security advisory being made public.

Initial estimates regarding the Coldcard security breach came from Rob Hamilton, who serves as CEO and co-founder of AnchorWatch, and calculated that approximately 594.48 Bitcoin, valued at roughly $38 million, had been transferred through 500 transactions occurring within a span of three blocks.

In subsequent analysis, Galaxy Research revealed that the transactions they identified exhibited a distinctive pattern, characterized by uniform 30 satoshis per virtual byte transaction fees and the absence of change outputs. According to the company, this specific pattern makes it possible to identify the initial attack activity on the blockchain, though they cautioned that subsequent attacks targeting Coldcard-generated addresses might not display identical characteristics.

In an X post shared on Friday, Rodolfo Novak, who serves as co-founder of Coinkite, acknowledged the company's responsibility for the firmware vulnerability and stated that efforts are underway to establish the complete extent of the security issue.

Novak explained that Coinkite has deployed a hotfix designed to eliminate the software fallback path, while emphasizing that this update cannot safeguard seeds that were created using the compromised firmware. He recommended that users who created their seeds on the vulnerable firmware versions should transfer their assets to wallets using newly generated seeds.