BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Galaxy Maps Warns Coldcard Bitcoin Losses After Wallet Incident

Galaxy Research, the research arm of Galaxy Digital, has expanded the on-chain footprint linked to the Coldcard wallet incident that reportedly resulted in the loss of 1,082.65 bitcoin. In a

AnonymousCryptoCompass newsroom
August 1, 2026
5 min read
NEWS
Galaxy Maps Warns Coldcard Bitcoin Losses After Wallet Incident
CryptoCompass editorial visual for bitcoin coverage.

Galaxy Research, the research arm of Galaxy Digital, has expanded the on-chain footprint linked to the Coldcard wallet incident that reportedly resulted in the loss of 1,082.65 bitcoin. In a new analysis, the firm identified 1,196 addresses that were involved in transactions tied to that event, widening the estimated scale beyond earlier preliminary figures.

The activity Galaxy Research points to took place between 1:10 AM and 1:51 AM UTC on July 30, spanning blocks 960,183 to 960,191—roughly 30 hours before Coldcard published its first security advisory, as referenced in Galaxy Research’s post on X.

Key takeaways

  • Galaxy Research traced a cluster of 1,196 addresses tied to the Coldcard incident, connected to losses of 1,082.65 BTC.
  • The movements were observed across blocks 960,183–960,191 between 1:10 AM and 1:51 AM UTC on July 30.
  • Galaxy Research says the transactions share a recognizable on-chain pattern (including identical fees and no change outputs), though later attacks may not reuse the same fingerprint.
  • Earlier estimates from Rob Hamilton and related analysis suggested a smaller, tighter window of activity that has since been superseded by the larger Galaxy Research mapping.
  • Coinkite has said it released a hotfix for a firmware bug, but users who created seeds using the vulnerable firmware may still need to move funds to a new seed.

Galaxy Research widens the address set

According to Galaxy Research, the incident’s impact is visible on-chain in a larger set of wallets than first documented publicly. The firm said it identified 1,196 addresses linked to the Coldcard wallet incident that ultimately resulted in 1,082.65 BTC being moved in the span it analyzed.

Galaxy Research’s tracing work focused on how those funds moved through the network during a specific period. It reported that the key transaction activity occurred between 1:10 AM and 1:51 AM UTC on July 30, crossing blocks 960,183 to 960,191.

That timing is also notable in terms of disclosure. Galaxy Research indicated this took place about 30 hours before Coldcard’s first security advisory was published.

From a smaller estimate to a larger on-chain pattern

Prior to Galaxy Research’s broader mapping, a preliminary view of the incident suggested a more limited sweep. Earlier analysis by AnchorWatch CEO and co-founder Rob Hamilton estimated that 594.48 BTC—worth around $38 million at the time—moved across roughly 500 transactions within a narrow three-block window.

Galaxy Research’s later work does not necessarily contradict the existence of that tight burst; instead, it expands the scope of what can be linked to the event by pointing to a repeatable transaction fingerprint.

In posts on X, Galaxy Research said the identified transactions share specific characteristics, including identical 30 satoshis per virtual byte fees and the absence of change outputs. Galaxy Research described these features as part of the method that allows the initial attack activity to be identified on-chain.

Importantly for users trying to assess exposure, Galaxy Research also cautioned that future attacks targeting Coldcard-generated addresses may not always follow the same on-chain “fingerprint.” That means wallet owners should not assume that the first set of identifiable traits will be reused in later attempts.

What Coinkite says about the firmware bug and the limits of updates

Coinkite co-founder Rodolfo Novak publicly addressed the issue via an X post on Friday, saying the company takes responsibility for the firmware bug and is working to determine the full scope of the problem.

Novak also said Coinkite released a hotfix intended to remove the software fallback path. However, he warned that installing the fix does not retroactively protect seeds that were generated using vulnerable firmware.

In practical terms, Novak advised users who created seeds on the vulnerable firmware to move their funds to a new seed. That distinction—between fixing a flaw going forward and securing already-generated keys—appears to be central to how users should interpret the incident response.

This is also a reminder that “device firmware updates” and “seed security” are not always interchangeable. If the vulnerability affected how seeds were generated or handled, a patch may stop new risk but cannot undo the exposure that may have occurred when the vulnerable firmware produced the original seed material.

Why the expanded tracing matters for incident assessment

The difference between Hamilton’s earlier estimate of 594.48 BTC and Galaxy Research’s later identification of 1,082.65 BTC underscores how incident accounting can evolve as analysts refine clustering techniques and expand time windows. Early on-chain forensics often focus on the clearest bursts; later work may connect additional wallets and transactions using shared traits like consistent fee patterns and transaction structure.

For traders and users, this matters because it changes how incident exposure can be understood. Wallet owners who are evaluating whether they need to move funds may face a moving target: a larger set of addresses suggests that more wallets could have been impacted than initially thought, while Galaxy Research’s warning about fingerprint variability implies that on-chain searches may not capture everything using a single pattern.

For developers and auditors, the episode also highlights the importance of both preventive controls and disclosure timing. Galaxy Research’s observation about the 30-hour gap between the analyzed activity and Coldcard’s first advisory publication frames the timeline in which users may have been acting on incomplete information.

As more details are verified, the key question for the broader ecosystem will be whether subsequent investigations confirm additional waves of activity beyond the identifiable on-chain pattern described by Galaxy Research—and whether Coinkite’s technical findings fully explain how the firmware behavior led to the reported losses.

Readers should watch for further updates from Coinkite on what the bug impacted at the seed level and for additional on-chain analysis that tests whether other clusters of transactions match or diverge from the fee and “no change output” fingerprint outlined by Galaxy Research.

This article was originally published as Galaxy Maps Warns Coldcard Bitcoin Losses After Wallet Incident on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.