/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Bitcoin hardware wallet Coldcard shipped a faulty firmware build, and hackers are now draining wallets; Galaxy Research estimates $70M+ stolen

More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly double the amount reported when the theft first surfaced.

CoinDesk Shaurya Malwa

Context & Ripple Effects

This incident follows a recurring pattern in which wallet software defects have exposed crypto holders: researchers previously identified a BitcoinJS flaw affecting older wallets, while Atomic Wallet investigated a separate wave of compromised accounts and stolen assets after its breach reports.

The Coldcard case matters because it places the failure in a hardware-wallet firmware release, concentrating losses across 1,196 wallets in a short window rather than in an isolated user-level compromise.

First-order effects

  • Holders whose wallets received the faulty Coldcard firmware have suffered direct bitcoin losses; Galaxy Research puts the reported total above $70 million.
  • Coldcard faces an immediate security and trust crisis tied to the integrity of its firmware distribution and release process.

Second-order effects

  • Other hardware-wallet providers will face sharper scrutiny of firmware signing, testing, and update controls as users reassess whether device-based self-custody sufficiently isolates them from software-release risk.
  • Recovery and tracing efforts become more consequential, echoing Atomic Wallet's attempt to block the sale of stolen assets, though the article does not establish whether the Coldcard losses can be recovered.

Third-order effects

  • If firmware-release failures recur, self-custody security will be judged less by a wallet's physical design than by the reliability of its full software supply chain.
  • The pattern—from older wallet-library flaws to this incident—suggests that wallet security risk remains systemic across implementations, potentially increasing demand for independently verifiable update processes.

The trend: Crypto custody is increasingly a software-supply-chain security problem, even when assets are held on dedicated hardware.

Discussion

  • @clay_garrett Clay Garrett on x
    1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addres…
  • r/CryptoCurrency r on reddit
    The Coldcard wallet exploit estimates have almost doubled to $70 million stolen of just over a thousand Bitcoins in 1,196 wallets drained in 41 minutes
  • r/Bitcoin r on reddit
    The Coldcard wallet exploit estimates have almost doubled to $70 million stolen of just over a thousand Bitcoins in 1,196 wallets drained in 41 minutes
  • @zynxbtc @zynxbtc on x
    The Bitcoin subreddit is absolutely heartbreaking right now. So many people have been destroyed. I recommend having a look because it gives you a different perspective compared to X. Really sad. [image]