Best Miami News connects businesses and publishers

collapse
Home / Daily News Analysis / How bitcoin cold wallets lost $70 million in an attack that never touched the devices

How bitcoin cold wallets lost $70 million in an attack that never touched the devices

Aug 07, 2026  Twila Rosenbaum 3 views
How bitcoin cold wallets lost $70 million in an attack that never touched the devices

More than 1,000 bitcoin, worth roughly $70 million at current market prices, were stolen from 1,196 Coldcard hardware wallets on July 30 in a sophisticated attack that never required physical access to the devices. According to Galaxy Research, the attacker recreated likely private keys by exploiting a weakness in the seed-generation process. The entire sweep happened in just 41 minutes, and it is believed to be nearly double the loss that was initially reported.

Key facts

  • More than 1,000 bitcoin, worth about $70 million, were drained from 1,196 Coldcard wallets.
  • The attack occurred in a 41-minute span on July 30.
  • The attacker never physically touched or accessed the hardware wallets.
  • Weak seed generation in certain firmware allowed the attacker to enumerate private keys offline.
  • Security researchers believe more wallets could be hit because owners cannot easily tell if their seeds were generated on vulnerable firmware.

Understanding cold wallets

Cold wallets are hardware devices designed to keep private keys offline. Unlike software wallets or exchange accounts, they are meant to be immune to remote attacks because secret material is stored in a dedicated chip and never exposed to an internet-connected environment. Transactions are signed offline and then broadcast through a connected app or a QR code. This makes them an attractive option for long-term holders and institutional investors seeking the highest level of self-custody.

The Bitcoin stored on these devices is not actually stored on the device itself. What the hardware wallet protects is the seed phrase, typically a sequence of 12 or 24 words, which is the master key to all the Bitcoin addresses controlled by that wallet. Anyone who knows that seed phrase can generate the corresponding private keys and move funds. That is why seed phrases are supposed to be generated from high-quality randomness and kept in a safe place. If a hardware wallet generates a weak seed, the physical device becomes almost irrelevant, because the seed can be recreated from outside.

A weakness in seed generation

Galaxy Research, a blockchain analytics and investment firm, said the attack took advantage of a firmware flaw in certain Coldcard hardware wallets. Coldcard devices have long been popular among security-focused Bitcoin users because of their air-gapped workflows and transparent code. This incident, however, shows that the security of a hardware wallet is only as strong as the randomness of the seeds it creates.

In a properly functioning BIP39 wallet, a seed phrase is derived from 128 to 256 bits of entropy. The entropy is generated by a cryptographic random number generator, and it should be computationally impossible to guess. The attacked firmware produced seeds that were not truly random, according to the researchers. The reduced entropy made the set of possible seed phrases small enough that an attacker could iterate through every candidate offline. For each candidate, the attacker could derive addresses and compare them to known balances on the Bitcoin network. Once a match was found, the private key was already in the attacker's control.

This approach is essentially the same method used in the old brain wallet attacks, where users generated private keys from simple passwords and attackers cracked them by computing thousands of passwords per second. The difference here is that the flaw was on the device side, not the user's choice. Users believed they were protected by a hardware device that had been designed to follow best practices, but the randomness source failed them.

Attack timeline and scale

The attack took place on July 30 and took just 41 minutes to drain more than 1,000 bitcoin from 1,196 wallets. At typical prices, that amount is valued at approximately $70 million. Early estimates put the loss at just over $35 million, but additional on-chain analysis revealed that the attacker had found more vulnerable wallets than initially identified.

The speed of the sweep suggests that the attacker had already done the difficult work before the funds were moved. They likely generated a long list of candidate seeds and associated addresses over an extended period, then executed the transfers in a single automated run to maximize the chance of success before the vulnerability was discovered. The 41-minute window reflects the time it took to broadcast and confirm the transactions, not the time it took to crack the seeds.

According to the research, the attacker appears to still be looking for more wallets generated by the same vulnerable firmware. The automated search can continue indefinitely because it does not require any interaction with the targets. As long as the weak seeds exist, there is a possibility that new matches will be found.

Why more wallets could be at risk

Security firms have warned that the full damage may not yet be known. A major concern is that many Coldcard owners cannot reliably determine whether their wallet was initialized with seeds generated by the vulnerable firmware. A firmware update can fix the bug for future seed generations, but it cannot retrofit randomness into an already created seed. If the seed was produced on a device with the flawed entropy source, it remains weak even if the firmware is updated later.

Users who are unsure about their devices are advised to move funds to a new wallet created with a fresh seed. This process involves generating a new wallet using trusted software, transferring a small test amount first, and then moving the full balance. The old wallet should be considered compromised if there is any chance it used the vulnerable firmware.

Hardware wallets themselves are not necessarily at fault. The attack did not exploit the secure element, the PIN mechanism, or the signing process. Instead, it targeted the upstream generation of the master key. That is an important distinction for the broader hardware wallet market. Even the best self-custody device can not protect funds when the secret it is built to guard has been recreated externally.

Lessons for Bitcoin users

This incident reinforces several fundamental security principles. First, randomness is the foundation of cryptographic security. A wallet can use the most advanced encryption algorithms and still be insecure if the randomness used to generate the key is poor. Second, wallet initialization is a critical moment. Users should only generate seeds using firmware that has been audited, widely reviewed, and verified to use a strong randomness source.

Third, monitoring the health of the Bitcoin network is an essential part of self-custody. This attack was detected only after researchers noticed on-chain patterns that were inconsistent with normal wallet behavior. The blockchain data provided clues about the scale and method of the attack, even though the attacker never left a traditional digital footprint.

Investigators are now tracing the stolen funds using logs from a blockchain data provider. The pseudonymous nature of Bitcoin makes it difficult to identify the attacker, but every transaction leaves a permanent record. If the funds are ever moved to a regulated exchange or mixed in large batches, analysts may be able to connect the attacker to an identity. Researchers say this type of trace is likely to continue for years.

The future of hardware wallet security

The attack is a reminder that cold storage is not a single product but a process. A hardware wallet is one component of a broader system that includes seed generation, backup storage, transaction verification, and firmware updates. A failure in any of those components can compromise the security of the entire system.

For the hardware wallet industry, the incident may lead to stronger requirements for audited entropy generation and better user education. It may also accelerate the move toward multi-signature arrangements, where a single compromised seed is not enough to spend funds. Multisig wallets require signatures from multiple independent devices or keys, which can reduce the risk of a single point of failure. While multisig adds complexity, it offers a powerful defense against seed-generation flaws of this kind.

Coldcard has long positioned itself as a premium device for Bitcoin users who prioritize security and transparency. Hardware wallet makers are now expected to review their entropy generation processes in light of the research. The broader Bitcoin community is waiting to see whether the affected firmware versions can be identified based on device serial numbers or software records.

Until then, the only safe course for users who may be affected is to treat their current wallet as compromised. Moving Bitcoin to a newly created wallet with fresh seeds is the fastest way to regain control over the funds. The attack did not require malicious code or physical tampering; it simply required the attacker to guess what the wallet thought was secret. That is a deeply uncomfortable thought for anyone who has trusted a hardware device to protect their savings, but it is also the reality of cryptography: a secret that is not truly random is not truly secret.


Source:Coindesk News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy