Coldcard Drain Mapping Expands Suspected Theft to 1,082 BTC
- 1,082.65 BTC was drained from 1,196 Bitcoin addresses due to a Coldcard vulnerability, expanding the initial theft report.
- Users of affected Coldcard firmware must generate new seeds to secure their funds, as upgrades do not fix existing vulnerabilities.
- Monitor the four principal addresses for any movement to assess the ongoing risk related to the Coldcard theft.
A new transaction mapping indicates that 1,196 Bitcoin addresses were fully drained between 01:10:20 and 01:51:26 UTC on July 30, moving 1,082.65 BTC across blocks 960,183 through 960,191. The sweep ended roughly 30 hours before hardware-wallet maker Coinkite issued its public advisory.
The mapping used a transaction pattern identified by engineers at Block and shared by Block engineer Clay Garrett. It expands the initially reported cluster of roughly 594.5 BTC, although neither Coinkite nor Block has publicly confirmed that every address in the larger set was compromised through the Coldcard flaw.
Identical Fees Point to Automation
Every mapped sweep reportedly paid an identical hardcoded fee rate of 30.0 sat/vB and created no change output. That was far above the 0.4–1.0 sat/vB median cited for the week, a pattern more consistent with one automated tool spending keys it already controlled than with hundreds of owners independently moving funds.
The affected set included 1,183 native SegWit addresses using BIP-84 derivation paths, seven BIP-49 addresses, and six BIP-44 addresses. The mix is consistent with multi-path wallet scanning, but the transaction pattern alone does not establish how the private keys were recovered.
Proceeds were consolidated within minutes into four principal addresses holding approximately 562.02 BTC, 398.48 BTC, 89.62 BTC, and 32.45 BTC. The balances had not moved again at the time of the analysis.
Firmware Fixes Leave Old Seeds Exposed
Block said Coldcard firmware could route seed generation through MicroPython’s deterministic software fallback instead of the intended hardware random-number generator. Its technical analysis described Mk2 and Mk3 version 4 firmware as following a fully vulnerable path and said later models retained constrained secure-element entropy, while noting that complete empirical exploit testing had not been conducted.
Coinkite’s updated security advisory says affected seeds include those generated on Mk3 firmware 4.0.1 through 4.1.9, Mk4 and Mk5 before 5.6.0, and Q before 1.5.0Q. The company has released fixed firmware, but upgrading does not repair an existing weak seed; users must generate a replacement and migrate funds unless sufficient independent dice entropy was added.
The next measurable development is any movement from the four consolidation addresses or further evidence connecting the expanded transaction cluster to the Coldcard vulnerability.
