/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Bitcoin hardware wallet Coldcard shipped a faulty firmware build, and hackers are now draining wallets; Galaxy Research estimates $70M+ stolen

More than 1,000 bitcoin, worth about $70 million, was drained from 1,196 wallets in a 41-minute window on July 30, nearly double the amount reported when the theft first surfaced.

CoinDesk Shaurya Malwa

Context & Ripple Effects

The reported losses extend a recurring pattern in crypto-wallet security incidents: an earlier BitcoinJS flaw put older wallets at risk, while Atomic Wallet previously sought to block the sale of assets after compromised accounts were reported. This case matters because the failure is tied to a firmware build for a hardware wallet, not simply an account-level compromise.

The revised estimate—more than 1,000 bitcoin drained from 1,196 wallets in 41 minutes—makes the scope materially clearer than the initial report and puts Coldcard's software-release process at the center of the incident.

First-order effects

  • Affected Coldcard users face irreversible bitcoin losses unless stolen funds can be identified and stopped before further movement; Galaxy Research's estimate places the theft above $70 million.
  • Coldcard must contain the faulty firmware's impact and account for how a build intended to protect self-custodied funds enabled wallet draining.

Second-order effects

  • Other hardware-wallet vendors and their users will have reason to scrutinize firmware distribution, signing, and update-verification controls, since the incident exposes release software as a high-value attack surface.
  • Wallet-recovery and transaction-monitoring efforts become more important after an event of this scale, echoing Atomic Wallet's earlier effort to block stolen assets from being sold.

Third-order effects

  • If similar incidents recur, hardware-wallet security will be judged less by the physical device alone and more by the integrity of its firmware supply chain and update process.
  • The episode reinforces that self-custody shifts operational responsibility to users and wallet makers rather than removing security risk; whether it changes adoption depends on Coldcard's containment and the broader industry's response.

The trend: Crypto self-custody is increasingly being tested by software and firmware supply-chain security, not only by exchange breaches or lost credentials.

Discussion

  • @clay_garrett Clay Garrett on x
    1/ During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps. That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addres…
  • @zynxbtc @zynxbtc on x
    The Bitcoin subreddit is absolutely heartbreaking right now. So many people have been destroyed. I recommend having a look because it gives you a different perspective compared to X. Really sad. [image]
  • r/CryptoCurrency r on reddit
    The Coldcard wallet exploit estimates have almost doubled to $70 million stolen of just over a thousand Bitcoins in 1,196 wallets drained in 41 minutes
  • r/Bitcoin r on reddit
    The Coldcard wallet exploit estimates have almost doubled to $70 million stolen of just over a thousand Bitcoins in 1,196 wallets drained in 41 minutes
  • @glxyresearch @glxyresearch on x
    🚨 A 3rd wave in what we suspect are hacks of Coldcard-generated addresses has been identified in which 207.7294 BTC has been drained. Our estimated observed size of the Coldcard hack is now 1,367.05 BTC (~$88.6m) across 4,585 addresses. More updates in the thread below 👇 [image]
  • @laurashin Laura Shin on x
    I had the thought that potentially there could be a white hat rescue similar to the DAO …
  • @truthcoin Paul Sztorc on x
    Not at all, It is draining the toxic anti-meritocracy SJW death-cult This is exactly the medicine Bitcoin needs We have not gone far enough
  • @waleswoosh @waleswoosh on x
    I can't keep my BTC on centralized exchanges because they might go bankrupt or freeze withdrawals. …
  • @epsilontheory Ben Hunt on x
    This Coldcard robbery is a big deal because it's draining small true-believer hodlers who “did everything right”. That's an incredibly powerful story arc. [image]
  • @nikzh Nikita Zhavoronkov on x
    Now, after losing his coins in the Coinkite accident, this Blockstream ex-employee finally understands …
  • @hodlonaut @hodlonaut on x
    The commits (code changes) that introduced Coldcard's low entropy bug, changed around 2500 lines of code. These were changes to the most important parts of their codebase, ensuring that the seeds have enough entropy so that.... your coins don't get stolen. The code comments for a…
  • @zherbert Zach Herbert on x
    NVK is currently deleting old posts from 2020 to try to clean up the history. Screenshot them while you can. They will all be gone soon. [video]
  • @francispouliot_ @francispouliot_ on x
    I really dislike justifying myself generally but I think sharing my rationale may be useful in this case. …
  • @hodlonaut @hodlonaut on x
    The code wouldn't compile, so the Coldcard dev DISABLED THE HARDWARE RNG (Random Number Generation) to make the error go away. …
  • @francispouliot_ @francispouliot_ on x
    Instructions for emergency migration from Coldcard Option 1: move funds to a mobile wallet Option 2: create a high-entropy wallet on coldcard with a strong passphrase These are temporary measure to immediately protect against Coldcard's entropy attack. Not long term storage solut…
  • @truthcoin Paul Sztorc on x
    Nvk is a serial liar — constantly lying about everything It blows my mind that (for example) …
  • @sesi_the_man @sesi_the_man on x
    Given the genesis point of everything going on right now, it's deeply ironic that today I find myself still addressing the same regurgitated @SeedSigner FUD, much of it originating from posts like this. Brandolini's Law continues to be in full effect. [image]
  • @zherbert Zach Herbert on x
    Regarding the Coldcard entropy bug - many folks are explaining what happened but I wanted …
  • @theretailbull Tim Lamb on x
    I've had all my bitcoin stolen while away on holiday.  It was on a Coldcard MK3. …
  • NullTX Will Izuchukwu on x
    Cold Wallets Can Now Be Exploited, Here Are 3 Most Secure Means For Your Assets
  • @odellxyz Odell on x
    i thought coldcard was the best and holy shit i was completely wrong have been trying my best to help people move for the last two days with no sleep, exhausted, broken, tragic my comms are overwhelmed by people, trying to respond to everyone if you are reading this and think you…
  • @martybent Marty Bent on x
    I think horror is the only word I can use to describe the feeling I've had since Thursday afternoon. I'm sorry to anyone who bought a Coldcard because of my endorsement. Like Matt, I've been on calls and text threads all weekend trying to help people get to safety. Please reach o…
  • @thebtctherapist @thebtctherapist on x
    Holy shit. 4 years ago someone reported their Coldcard wallet got drained after using the RNG feature with no dice rolls and he was subsequently blocked by Coldcard. They had 4+ years to address this issue. This horror story just keeps getting worse. H/t: @Zenul_Abidin [image]