Galaxy puts the Coldcard drain at 1,082 BTC across 1,196 wallets — roughly double the first count
Galaxy Research says an attacker swept 1,082.65 BTC from 1,196 Coldcard wallets in 41 minutes on July 30 by reconstructing weakly generated seeds offline, without touching a single device.
An attacker moved 1,082.65 BTC — about $70 million at current prices — out of 1,196 Coldcard hardware wallets between 01:10 and 01:51 UTC on July 30, according to a Galaxy Research reconstruction published Friday and reported by CoinDesk. That is close to double the roughly $38 million CoinDesk itself reported when the theft surfaced a day earlier; Galaxy attributes the gap to early reporting capturing only one of the four destination addresses. The proceeds have not moved from those four addresses.
The mechanism is the story. Per Galaxy's account, an internal build setting in certain Coldcard firmware told the device to skip its dedicated hardware random number generator, and a check in a supporting library tested only whether that setting existed rather than whether it was enabled. Key generation fell back to a software substitute seeded from the chip's factory serial number and its clock registers — one fixed value, one an attacker can narrow or measure on a device they own themselves.
That collapsed the space of possible keys to something enumerable. Security teams found generation on the older Mk2 and Mk3 could be determined outright; on the Mk4, Q and Mk5 they put the range at roughly four billion candidates. An attacker generates candidates on their own machine, derives the addresses, and checks them against the public chain. The victim's device is never involved.
Galaxy's breakdown supports brute-force enumeration rather than targeting: 1,183 drained wallets used native segwit, seven an older standard, six an older one still, and the sweeps landed across six blocks with three empty blocks interleaved — consistent with batched broadcasts. Galaxy warned further waves are likely, and says there is no test an owner can run to learn whether their own seed falls inside the reproducible range.
Block's Clay Garrett said on X that the operator queried source addresses during the sweeps through a paid account at a "well-known blockchain-services provider," and that the provider's internal logs matched the suspected workflow down to the number, timing and sequence of requests. Block has passed the information to authorities. The provider is not named and appears to have been serving ordinary requests.
Key facts
- 1,082.65 BTC (~$70M) from 1,196 wallets, 01:10–01:51 UTC July 30 — Galaxy Research, via CoinDesk
- Earlier figure ~$38M, one address; final count spans four addresses, funds unmoved — CoinDesk
- Key range ~4 billion on Mk4/Q/Mk5; determinable on Mk2/Mk3 — security teams cited by CoinDesk
- Address mix: 1,183 native segwit / 7 / 6 across older formats — Galaxy Research
- Operator traced via paid blockchain-data account logs — Clay Garrett (Block) on X
The real-world read
Two named parties give different scopes. Coinkite, Coldcard's maker, has warned Mk3 owners and says its newer devices are unaffected. Block's report places the Mk2, Mk4, Q and Mk5 in scope as well. Both cannot be right, and the disagreement is between the vendor and an outside researcher — the vendor's version is the narrower one, and it is the vendor's product. Until that is settled, owners have no way to verify their own exposure.
Note also what "$70 million" rests on: a single research firm's reconstruction, one day after a $38 million figure from the same outlet. Galaxy explains the revision, but the number is one party's count, not a confirmed total, and Galaxy says the search may still be running. CoinDesk's own earlier headline framed the incident as something that "may push investors to ETFs" — a framing that serves products, not readers, and that nothing in Galaxy's or Block's findings supports. The tacked-on reference to Anthropic post-quantum research is CoinDesk's context, not part of this incident.
Opinion, and whose
Galaxy Research: further waves are likely if owners do not move funds. Clay Garrett (Block): the provider log match was "extraordinar[ily]" specific. CoinDesk's own reading — that this shakes faith in self-custody — is the outlet's, and it is a forecast, not a finding.
Sources
- CoinDesk (Aug 1, 2026) — the full account; relays Galaxy Research's reconstruction, Coinkite's advisory and Block's findings. Secondary throughout.
- Galaxy Research, via CoinDesk — timing, block distribution, wallet and address-format counts, BTC total.
- Clay Garrett, Block, on X (July 31, 2026) — the data-provider log trail.
- Coinkite — vendor advisory, as characterized by CoinDesk. Vendor statements about its own product scope.
- Not used: a Binance "case study" promotional unit on the same CoinDesk page. That is marketing, not reporting.
Nothing here is financial advice.