Login
Sign Up
Woofun AI reports that Galaxy Research, the analytical division of Galaxy Digital, has quantified the financial impact of the Coldcard wallet incident, attributing the losses to a critical firmware vulnerability managed by Coinkite co-founder Rodolfo Novak.
The investigation pinpointed 1,196 addresses involved in the exfiltration of 1,082.65 Bitcoin, totaling approximately $70.2 million at the time of transfer. These transactions occurred between 1:10 AM and 1:51 AM UTC on July 30, spanning blocks 960,183 to 960,191, roughly 30 hours prior to Coldcard’s initial security advisory. As detailed in an X post on Friday, the activity was characterized by uniform 30 satoshis per virtual byte fees and the absence of change outputs.
Woofun AI data shows this figure significantly exceeds earlier estimates by AnchorWatch CEO Rob Hamilton, who had identified 594.48 Bitcoin worth $38 million moving across 500 transactions within a three-block window. Galaxy Research noted that while these initial movements share an identical on-chain fingerprint, future exploits targeting Coldcard-generated addresses may not replicate this specific pattern.
Rodolfo Novak acknowledged the firmware bug and confirmed the release of a hotfix to eliminate the software fallback path, though he emphasized the update does not secure seeds generated on vulnerable firmware. Users are advised to migrate funds to a new seed immediately, marking a critical response to the full scope of the breach.