Galaxy Research traces $70M Coldcard breach: 1,196 BTC addresses, 1,082.65 BTC stolen

Galaxy Research (Galaxy Digital) says it traced the Coldcard breach to 1,196 compromised addresses. The attackers stole 1,082.65 BTC, worth about $70.2 million at the time of the transactions. On-chain monitoring tracked the BTC transfers between 01:10–01:51 UTC on July 30 (blocks ~960,183–960,191), around 30 hours before Coldcard issued its first security advisory. Galaxy also identified an attack “fingerprint”: identical transaction fee patterns (30 satoshis per vbyte) and no change outputs, suggesting a coordinated initial push. Galaxy warned that follow-on attacks on other Coldcard-generated addresses may not reuse the same pattern. Coinkite, Coldcard’s manufacturer, confirmed the vulnerability and released a firmware hotfix to remove the flawed software fallback path. However, it stressed that firmware updates do not protect seeds created on vulnerable firmware. Users are urged to move funds to assets generated with a new seed. For traders, this Coldcard breach is a reminder of persistent hardware wallet attack surfaces. The most likely effect is short-term risk caution around self-custody headlines, while longer-term impact depends on whether more disclosures trigger broader de-risking tied to BTC holdings.
Neutral
This is primarily a wallet-security incident, not a protocol or market-structure change for BTC. Short-term, the detailed on-chain findings and the timeline gap before Coldcard’s advisory can increase caution and reduce risk appetite for self-custody, which may move sentiment around BTC holdings. Long-term, market impact should remain limited unless additional disclosures expand the affected population or trigger exchange/portfolio de-risking specifically for BTC. Since Galaxy also notes future attacks may not match the same fingerprint, contagion risk to the broader BTC ecosystem looks constrained.