1
1
Galaxy Research, the dedicated research division of the prominent crypto investment firm Galaxy Digital, has significantly updated the estimated financial impact of the recent Coldcard wallet incident. Their in-depth analysis has identified 1,196 distinct Bitcoin addresses that collectively lost a substantial 1,082.65 Bitcoin. At the time these transactions occurred, this amount was valued at approximately $70.2 million. This revised figure represents a considerable expansion of the previously understood scope of the security vulnerability affecting Coldcard wallets.
The tracing of these Bitcoin movements by Galaxy Research provides a precise timeline and context for the incident. The suspicious transactions were observed to have taken place between 1:10 AM and 1:51 AM UTC on July 30th. This timeframe spanned across Bitcoin blocks numbered 960,183 to 960,191. The discovery and analysis by Galaxy Research occurred approximately 30 hours prior to Coldcard officially publishing its first security advisory regarding the issue. This information was shared via an X (formerly Twitter) post on Friday, shedding light on the investigation’s progression.
Prior to Galaxy Research’s comprehensive report, an earlier preliminary analysis of the Coldcard incident was conducted by Rob Hamilton, the CEO and co-founder of AnchorWatch. Hamilton’s initial assessment had estimated the losses to be around 594.48 Bitcoin, a sum then valued at approximately $38 million. This earlier estimate was based on the observation of roughly 500 transactions that occurred within a narrower three-block window. While Hamilton’s findings provided an initial indication of the problem, Galaxy Research’s subsequent investigation has revealed a more extensive and costly impact.
The detailed findings from Galaxy Research have further elucidated the nature of the compromised transactions. The firm noted that the identified Bitcoin movements shared a distinct and identifiable pattern. A key characteristic of these transactions was the use of identical fees, specifically 30 satoshis per virtual byte. Another significant observation was the absence of any "change outputs" in these transactions. This lack of change outputs is often indicative of a controlled or automated process rather than typical user behavior.
According to an X post from Galaxy Research, this unique pattern allows for the initial attack activity to be identifiable on the Bitcoin blockchain. This on-chain forensic capability is crucial for understanding how the exploit was executed. However, the research team also issued a critical caveat: future attacks targeting addresses generated by Coldcard may not necessarily follow the same discernible fingerprint. This implies that while the current incident’s pattern is identifiable, the attackers could adapt their methods, making future detection more challenging if a similar vulnerability were to be exploited again.
In response to the unfolding situation, Rodolfo Novak, the co-founder of Coinkite, the company behind Coldcard, acknowledged the gravity of the incident. In an X post on Friday, Novak stated that Coinkite takes full responsibility for the firmware bug that led to the security breach. He confirmed that the company is actively engaged in a thorough process to determine the complete scope and ramifications of the issue. This transparent admission of responsibility is a significant step in addressing the concerns of their user base.
Novak further elaborated on the immediate remedial actions taken by Coinkite. He announced that the company had released a "hotfix" for the Coldcard firmware. The primary objective of this hotfix was to remove a specific "software fallback path" that was exploited. However, Novak issued a stern warning alongside this update: the released hotfix does not provide protection for Bitcoin seeds that were generated on vulnerable firmware versions prior to the fix. This means that users who created their seed phrases while their Coldcard was running the compromised firmware remain at risk.
Consequently, Novak strongly advised all users who generated their seeds on vulnerable firmware to take immediate action to secure their funds. The recommended course of action is to move all assets to a newly generated seed phrase on a device that has been updated to the secure firmware. This proactive measure is essential for mitigating the ongoing risk to these users’ Bitcoin holdings.
The incident highlights the critical importance of robust security practices in the cryptocurrency hardware wallet space. While Coldcard is generally regarded as a highly secure option, even sophisticated devices can be vulnerable to firmware flaws. The swiftness of the analysis by Galaxy Research and the transparent communication from Coinkite are crucial elements in managing such security breaches.
The financial implications of this Coldcard incident, now estimated at $70 million, underscore the significant value at stake in the cryptocurrency ecosystem. The identification of a specific attack pattern is a valuable piece of information for blockchain analytics firms and security researchers. However, the warning that future attacks may evolve serves as a reminder of the constant cat-and-mouse game between attackers and defenders in the digital asset world.
Users of hardware wallets are consistently advised to keep their devices updated with the latest firmware, to use strong and unique security measures, and to be vigilant about any unusual activity related to their funds. The Coldcard incident serves as a potent case study in the potential consequences of even a single firmware vulnerability, emphasizing the need for continuous security audits and rapid response mechanisms within the industry. The ongoing investigation by Coinkite aims to provide further clarity and ensure that such vulnerabilities are addressed comprehensively.