Bitcoin Vaults Gutted in 41 Minutes

Bitcoin coins on a reflective surface.
BITCOIN VAULTS IN TROUBLE

One tiny software bug in a “safe” Bitcoin wallet quietly turned 4,585 savings accounts into an $89 million feeding frenzy for a single attacker.

Story Snapshot

  • About 1,082.65 Bitcoin vanished from 1,196 addresses in just 41 minutes on July 30.
  • Three attack waves drained roughly 1,367 Bitcoin, worth around $88–89 million, from Coldcard-linked wallets.
  • A hidden firmware mistake crippled the wallet’s random-number generator, making seed phrases guessable offline.
  • The incident shattered faith in “air-gapped” self-custody and raised hard questions about crypto security and personal responsibility.

The night $70 million in Bitcoin vanished in under an hour

Galaxy Research analysts watched something chilling on July 30: 1,196 Bitcoin addresses drained almost in unison, with 1,082.65 Bitcoin swept out in a 41-minute window. These were not clumsy retail traders panic-selling.

They were quiet, long-dormant wallets, many tied back to Coldcard hardware devices that owners believed were the gold standard of “offline” safety.

One automated attacker script moved like a high-speed vacuum cleaner across the blockchain, leaving nothing but empty addresses and stunned victims.

The pattern was too precise to be random. Galaxy Research traced the outflows into a small cluster of attacker-controlled addresses and flagged that nearly all of the victims had one thing in common: they had generated their seed phrases using Coldcard devices manufactured by Canadian firm Coinkite.

Shortly after, Block’s Bitcoin engineering team publicly tied the incident to a firmware vulnerability that dated back to 2021, confirming that something deep inside the wallet’s code had failed.

Three waves of theft revealed the full scale of the flaw

The first wave grabbed the headlines, but it was only the opening punch. Over the next days, researchers documented additional sweeps that turned a shocking hack into one of Bitcoin’s biggest hardware wallet failures on record.

A second wave drained tens of Bitcoin from thousands of lower-value addresses, and a third wave added roughly 207.73 Bitcoin from 1,912 more, pushing the tally to about 1,367 Bitcoin stolen from 4,585 addresses — nearly $89 million at prevailing prices.

The attack clearly targeted a specific population: wallets whose seeds were generated on vulnerable Coldcard firmware versions dating back to March 2021.

Coinkite later confirmed that Coldcard Mk3 firmware starting at version 4.0.1, along with some Mk4, Mk5, and Q devices before recent patches, had produced seeds with dangerously weak randomness.

Once researchers understood that link, the three waves looked less like isolated crimes and more like someone draining a known pool of easy-to-crack piggy banks.

The bug that turned “random” seed phrases into predictable keys

The heart of the failure was not a flashy zero-day or clever social engineering. It was a simple firmware configuration mistake that downgraded Coldcard’s seed generation from true hardware randomness to a predictable software fallback.

Instead of using the device’s hardware random-number generator, some Coldcard builds quietly used a deterministic software generator that relied on non-secret data — numbers that an attacker could model or reproduce.

That change gutted the entropy, or unpredictability, of the seed phrases. Security researchers estimate that affected seeds effectively shrank from strong 128-bit randomness to something closer to 40 bits, putting them well within reach of focused offline brute force.

In plain English, the seed phrase protecting people’s life savings went from “practically impossible to guess” to “painful but doable with time and computing power.”

What this exploit exposed about self-custody and trust

Coinkite did issue a security notice on July 30, warning Coldcard Mk3 owners that any seeds created since March 2021 might be unsafe and urging them to move funds.

For many victims, that alarm came hours too late. The first big sweep of roughly 594 Bitcoin from about 500 wallets happened in a tight half-hour window before most regular users were even awake to read a blog post or email. The message was brutal: when the tool you rely on for “sovereign” money fails, there is no bank fraud department coming to reverse the charge.

For years, hardware wallets were sold as the “grown-up” choice in crypto — a way to take responsibility, get off fragile exchanges, and guard wealth offline. This exploit did not disprove self-custody; it showed how fragile that promise becomes when basic engineering discipline slips.

The attacker needed no physical access, no phishing, no malware on victims’ machines. They only needed one wallet maker to ship a weak random-number generator and thousands of owners to trust it blindly.

Where this leaves Coldcard users and Bitcoin security

By early August, Galaxy Research and other forensic teams were clear: the observed loss total reached about 1,367 Bitcoin from 4,585 addresses, with funds still largely parked in a handful of attacker-controlled addresses.

Coinkite has since moved to patch the affected firmware lines and warned users to regenerate seeds on fixed versions. But patches cannot restore stolen coins. They can only stop the bleeding for those lucky enough to have held funds in vulnerable wallets that have not yet been drained.

For everyday Bitcoin holders, the lesson is sharp but useful. Self-custody is still the closest thing to financial freedom many people will ever see. Yet freedom without verification is just blind faith. The Coldcard exploit shows that “trust, but verify” is more than a slogan; it is a survival rule.

Choosing tools with transparent security reviews, real randomness, and honest communication is not paranoia. It is when a single bug can erase $89 million in less time than it takes to watch a TV drama.

Sources:

foxbusiness.com, thehackernews.com, coindesk.com, crypto.news, techspot.com, cryptopolitan.com, finance.yahoo.com, youtube.com, kucoin.com, bingx.com