Galaxy Research Widens Coldcard Wallet Incident Scope
Galaxy Research has expanded on its analysis of the Coldcard wallet incident that resulted in the loss of 1,082.65 BTC. The firm identified 1,196 addresses involved in transactions tied to the event, a wider scope than earlier estimated.
The activity took place between 1:10 AM and 1:51 AM UTC on July 30, across blocks 960,183 to 960,191 - roughly 30 hours before Coldcard published its first security advisory. Galaxy Research notes that the transactions share a recognizable on-chain pattern, including identical fees of 30 satoshis per virtual byte and no change outputs.
However, the firm warns that later attacks may not reuse the same fingerprint, making it essential for wallet owners to reassess their exposure. Coinkite co-founder Rodolfo Novak has acknowledged the firmware bug and released a hotfix to remove the software fallback path, but users who generated seeds using vulnerable firmware still need to move funds to a new seed.
This incident highlights the importance of preventive controls and timely disclosure for developers and auditors. Galaxy Research's expanded tracing also underscores the evolving nature of on-chain forensics, as analysts refine their techniques and expand time windows.