Bitcoin hardware wallet Coldcard shipped a faulty firmware build, and hackers are now draining wallets; Galaxy Research estimates $70M+ stolen
More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly double the amount reported when the theft first surfaced.
Context & Ripple Effects
This incident follows a recurring pattern in which wallet software defects have exposed crypto holders: researchers previously identified a BitcoinJS flaw affecting older wallets, while Atomic Wallet investigated a separate wave of compromised accounts and stolen assets after its breach reports.
The Coldcard case matters because it places the failure in a hardware-wallet firmware release, concentrating losses across 1,196 wallets in a short window rather than in an isolated user-level compromise.
First-order effects
- Holders whose wallets received the faulty Coldcard firmware have suffered direct bitcoin losses; Galaxy Research puts the reported total above $70 million.
- Coldcard faces an immediate security and trust crisis tied to the integrity of its firmware distribution and release process.
Second-order effects
- Other hardware-wallet providers will face sharper scrutiny of firmware signing, testing, and update controls as users reassess whether device-based self-custody sufficiently isolates them from software-release risk.
- Recovery and tracing efforts become more consequential, echoing Atomic Wallet's attempt to block the sale of stolen assets, though the article does not establish whether the Coldcard losses can be recovered.
Third-order effects
- If firmware-release failures recur, self-custody security will be judged less by a wallet's physical design than by the reliability of its full software supply chain.
- The pattern—from older wallet-library flaws to this incident—suggests that wallet security risk remains systemic across implementations, potentially increasing demand for independently verifiable update processes.
The trend: Crypto custody is increasingly a software-supply-chain security problem, even when assets are held on dedicated hardware.