Crypto加密$BTC

Bitcoin losses tied to Coldcard vulnerability reach $70 million, Galaxy Research finds

Hardware wallet security is under fresh scrutiny after Galaxy Research linked roughly $70 million in Bitcoin losses to a vulnerability affecting Coldcard signing devices. Galaxy said nearly 1,200 addresses were drained of more…

By Sofia Almeida·August 1, 2026·二〇二六年八月一日·2 min read

Key takeaways

  • Galaxy Research linked roughly $70 million in Bitcoin losses to a vulnerability affecting Coldcard signing devices.
  • Galaxy said nearly 1,200 distinct addresses were drained of more than 1,000 BTC, attributing the figure directly to the flaw.
  • Galaxy's publicly available summary does not specify the attack vector, leaving the exact mechanism in the Coldcard stack unconfirmed.
  • The losses came from users holding their own keys on a hardware device, testing the security case for self-custody cold storage.
  • It remains open whether the nearly 1,200 affected addresses are the full count of vulnerable wallets or a subset of a larger at-risk population.

Hardware wallet security is under fresh scrutiny after Galaxy Research linked roughly $70 million in Bitcoin losses to a vulnerability affecting Coldcard signing devices. Galaxy said nearly 1,200 addresses were drained of more than 1,000 $BTC, a figure the firm attributed directly to the flaw.

What the on-chain record shows

The breadth of Galaxy Research's figure points to systematic exploitation. Nearly 1,200 distinct addresses drained of more than 1,000 BTC implies the vulnerability was repeatable at scale across a large address population. Galaxy's publicly available summary does not specify the attack vector, leaving the exact mechanism in the Coldcard stack unconfirmed.

Coldcard is a Bitcoin hardware signing device built for cold storage and offline key management. Losses traced to the device itself carry a different weight than exchange hacks: the user held their own keys and was still drained. That distinction matters for how the security community will interpret the event.

The custody argument under pressure

Against the backdrop of exchange failures in prior years, hardware wallets became the default answer for Bitcoin holders trying to eliminate third-party exposure. The $70 million figure Galaxy Research has published tests that argument directly. Self-custody shifts risk from institutions to the individual holder, and it depends entirely on the integrity of the hardware layer.

Bitcoin's demand environment for secure cold storage has expanded alongside institutional allocation. A confirmed breach in a widely used signing device at this scale will prompt reassessment from security researchers and from holders who assumed cold storage was the safest available option. For those holding $BTC outside of exchanges, the assumption that a hardware device eliminates counterparty risk now requires scrutiny.

The unresolved question

Galaxy Research placed total losses at more than 1,000 BTC worth roughly $70 million. What remains open is whether the nearly 1,200 affected addresses represent the full count of vulnerable wallets or a subset of a larger at-risk population. That distinction will determine the residual exposure for Coldcard users who have not yet seen funds move.

Related reading

Source · 來源

theblock.co

Share · 分享

Frequently asked

How much Bitcoin was lost due to the Coldcard vulnerability?

Galaxy Research placed total losses at more than 1,000 BTC, worth roughly $70 million.

How many addresses were affected?

Nearly 1,200 distinct addresses were drained, according to Galaxy Research.

What is Coldcard?

Coldcard is a Bitcoin hardware signing device built for cold storage and offline key management.

Is the exact attack method known?

No; Galaxy's publicly available summary does not specify the attack vector, so the exact mechanism in the Coldcard stack remains unconfirmed.

Why does this loss matter for self-custody?

Because users held their own keys on a hardware device and were still drained, the event tests the assumption that cold storage eliminates counterparty risk and prompts reassessment of hardware wallet security.