What exactly happened?
According to Cointelegraph, analytics firm Galaxy Research identified 1,196 addresses from which 1,082.65 bitcoin disappeared during a 41 minute window. The Block reports it involved nearly 1,200 addresses and over 1,000 BTC worth roughly $70 million. The two figures essentially match and push the estimated scope of the incident higher.
The losses are linked to a vulnerability in the Coldcard hardware wallet. A hardware wallet is a device meant to protect an existing private key through secure storage, offline transaction signing, and on-device verification.
What is the flaw?
According to CryptoSlate, the issue is a defect in how some Coldcard devices generate the seed (the initial random number from which all of the wallet's private keys are derived). Coinkite, the maker of Coldcard, says funds tied to seeds generated on firmware 4.0.1 or later on the Mk3 model may be at risk.
CryptoSlate quotes a Bitcoin Core contributor going by instagibbs, who said he managed to recreate a vulnerable seed on a freshly initialized Mk3 device. That is the heart of the problem: if a seed can be reproduced, an attacker can derive the same private keys.
According to Coinkite, Mk4 and Mk5 devices are also affected, specifically before firmware 5.6.0, along with Q models before version 1.5.0Q. For these devices, CryptoSlate reports the firm describes the impact as less severe but still serious.
How much of this is proven?
It is confirmed that Galaxy Research published specific figures (the number of addresses and the volume of BTC). It is also confirmed that Coinkite described the affected firmware versions and plans a formal technical breakdown of the root cause.
What is not yet clear: the exact mechanism of how attackers obtained the keys across all affected addresses, whether the drain was carried out by a single actor or multiple independent parties, and whether the final figure of $70 million will keep rising or settle. According to CryptoSlate, the formal cause analysis is still to come.
Timeline and figures
| Data point | Value | Source |
|---|---|---|
| Affected addresses | 1,196 (Galaxy), nearly 1,200 (The Block) | Cointelegraph, The Block |
| BTC drained | 1,082.65 BTC | Cointelegraph |
| Drain window | 41 minutes | Cointelegraph |
| Estimated value | roughly $70 million | The Block |
| Affected Mk3 firmware | 4.0.1 and later | CryptoSlate |
| Affected Mk4/Mk5 firmware | before 5.6.0 | CryptoSlate |
| Affected Q firmware | before 1.5.0Q | CryptoSlate |
What did CZ say about it?
According to CoinDesk, Binance founder Changpeng Zhao (CZ) noted after the incident that even hardware wallets can contain bugs, and he argued for spreading funds across multiple wallets. Charliedesk does not give investment or security advice; we present this as a statement from a specific person, not as a recommendation.
What to watch out for with this type of event
With incidents involving key generation, it is essential to separate two things: the confirmed scope (how much in funds provably disappeared and from how many addresses) and the hypothesis about the cause (how exactly it happened). At this moment the scope is firmly documented per Galaxy Research, while Coinkite has only promised a complete technical explanation. Charliedesk will track whether the $70 million estimate changes once the formal breakdown is published.

