A forensic analysis by Galaxy Research has materially expanded the known scope of the Coldcard wallet incident, identifying 1,196 compromised addresses that collectively lost 1,082.65 Bitcoin — a sum now valued at approximately $70 million — all drained within a staggering 41-minute window. The findings reframe what was already a significant security event into one of the more alarming coordinated thefts in hardware wallet history, raising urgent questions about the attack vector, the reach of the vulnerability, and what it means for the broader community of users who trusted air-gapped hardware to be their last line of defense.
The Anatomy of a 41-Minute Drain
What makes Galaxy Research's analysis particularly striking is not just the dollar figure — though $70 million is by any measure a devastating sum — but the operational precision implied by the timeline. Draining 1,082.65 BTC across nearly 1,200 discrete addresses in 41 minutes requires either a highly automated execution pipeline or extraordinary coordination. This was not opportunistic cherry-picking of a handful of high-value wallets. It was a systematic sweep, the kind that suggests the attacker had pre-mapped targets and pre-signed or pre-authorized transactions well before the execution phase began. The 41-minute window is the tell: someone had already done the hard work before the clock started.
Galaxy's methodology — tracing on-chain activity across those 1,196 addresses — is the kind of blockchain forensics that transforms an incident from a rumor into a documented event with quantifiable scope. Prior estimates had placed the losses lower; this analysis expanded the picture considerably. The implication is that the initial public accounting undercounted affected users, and there may be victims who have not yet realized their funds are gone or have not come forward publicly.
Coldcard's Reputation Under the Microscope
Coldcard hardware wallets have long occupied a particular position in the Bitcoin security ecosystem. Manufactured by Coinkite, they are widely regarded as among the most security-conscious consumer hardware wallets available — favored by cypherpunks, self-custody advocates, and institutional-adjacent holders who treat the device's air-gap architecture and open-source firmware as non-negotiable requirements. The brand's entire value proposition rests on the assumption that private keys generated and stored on the device cannot be extracted remotely. An incident of this scale, affecting this many addresses simultaneously, directly challenges that foundational claim — or at minimum demands a transparent and technically rigorous accounting of what actually went wrong.
The hardware wallet sector has faced scrutiny before. Ledger's 2020 customer data breach exposed the personal information of over a million users, and the company's 2023 ConnectKit supply chain compromise sent shockwaves through the decentralized finance ecosystem. But those incidents, serious as they were, did not result in direct, large-scale Bitcoin losses of this magnitude in such a compressed timeframe. The Coldcard incident, as characterized by Galaxy's numbers, occupies different and more troubling territory.
Supply Chain, Firmware, or User-Side Compromise?
The critical question that Galaxy's on-chain analysis alone cannot fully answer is the nature of the vulnerability itself. Three broad categories typically explain events of this type: a supply chain compromise affecting device hardware or firmware before it reaches end users; a software-side exploit targeting the signing or key derivation process; or a coordinated user-side attack leveraging phishing, seed phrase harvesting, or social engineering at scale. The simultaneity of the 41-minute drain window argues against a slow-burn user-side campaign — that profile typically produces losses spread over days or weeks, not a synchronized multi-address sweep. The compressed timeline points more toward an attacker who held pre-existing access to private key material and chose a specific moment to liquidate.
If the compromise involved firmware or the supply chain, the potential blast radius extends well beyond the 1,196 addresses identified so far. Users who have not yet moved their funds could still be exposed. That uncertainty — the possibility that the Galaxy figure is a floor, not a ceiling — is perhaps the most consequential dimension of this story for anyone currently holding Bitcoin on a Coldcard device.
What This Means for Hardware Wallet Holders
For the self-custody community, this incident arrives at a complicated moment. Bitcoin's price appreciation has made hardware wallet security a genuinely high-stakes concern for a far larger population than the cypherpunk cohort that originally championed devices like Coldcard. The average wallet balance among affected addresses implied by Galaxy's numbers — roughly 0.9 BTC per address — suggests these were not all large institutional holdings but included everyday holders whose entire savings may have been wiped in under an hour.
The immediate practical response for any hardware wallet holder — not just Coldcard users — is to treat the situation as a forcing function for reviewing their security posture. That means verifying firmware authenticity, auditing seed phrase storage practices, and monitoring on-chain activity on all associated addresses. More broadly, the industry needs a faster, more transparent incident response framework. Galaxy's analysis is valuable precisely because it gives the community quantified facts to work with. The question now is whether Coinkite and the wider security research community can produce an equally rigorous technical post-mortem — one that explains not just what happened, but whether any funds at risk remain exposed today.
Written by the editorial team — independent journalism powered by Bitcoin News.