Galaxy Research: 1,367 BTC Stolen in Coldcard Mk3 Firmware Exploit

AI Market Summary
Galaxy Research reports 1,367.05 BTC (~$88.6M) was stolen via a Coldcard Mk3 firmware RNG weakness affecting seeds generated on versions 4.0.1+ (introduced 2021), with three coordinated sweep waves and minimal post-theft fund movement. The revision materially increases estimated losses and highlights systemic self-custody risk for single-signature users on compromised devices, potentially weighing on near-term Bitcoin sentiment and custody-provider scrutiny.
Impact level
● Medium
Affected assets
BTC/USDT-0.10%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Galaxy Research says a firmware vulnerability in Coldcard Mk3 hardware wallets enabled attackers to steal 1,367.05 BTC, about $88.6 million, in three coordinated waves that affected 4,585 addresses. The new estimate is far larger than initial reports that suggested roughly 594 BTC was taken from about 500 addresses. Galaxy's on-chain review indicates a wider, more systematic operation. The biggest sweep occurred on July 30, 2026, when attackers drained 1,082.65 BTC (around $70.2 million) in 41 minutes. Galaxy found the first two waves carried nearly identical transaction signatures, including hardcoded fees of 30 sat/vB and matching batching behavior, pointing to a single operator or shared tooling. The third wave deviated from that pattern, suggesting either a different actor or a tactical change. Most of the stolen BTC has not meaningfully moved and remains concentrated in a small set of attacker-controlled addresses. Galaxy attributes the breach to predictable randomness: a weakness in the Mk3 firmware random number generator that affects versions 4.0.1 and later, introduced in March 2021. The flawed RNG produced weak, predictable seed material. With sufficient computing power, an attacker could enumerate possible seeds offline, link them to real blockchain addresses, and sweep funds from single-signature wallets without physical access to the device. Block's engineering team is credited with first publicly flagging the RNG issue. Coinkite, the maker of Coldcard, published an advisory about 30 hours after the initial sweeps began. Coldcard Mk4, Q, and Mk5 devices are not believed to share the same flaw. Users with funds tied to potentially impacted Mk3 wallets are being urged to generate entirely new seeds on unaffected models, rather than simply moving balances within the same hardware generation. Galaxy also highlighted fee behavior during the thefts: the hardcoded 30 sat/vB used in the first two waves was roughly 30 to 75 times the median fee at the time, indicating the attackers were willing to pay up for fast confirmations. For Coldcard Mk3 users running firmware version 4.0.1 or newer, the recommendation is to treat existing seeds as potentially compromised and migrate funds to a newly generated wallet on unaffected hardware. Reviewing firmware history and checking Coinkite's advisory are the immediate steps.