Galaxy Research: The Coldcard loophole has resulted in over $70 million in lost bitcoin assets, and nearly 1,200 addresses have been emptied
On 1 August, Galaxy Research stated that the incident related to the Coldcard hardware wallet loophole had resulted in the emptiness of nearly 1,200 addresses, involving a total of 1082.65 BTCs valued at approximately $7.02 million. An analysis of financial flows shows that on 30 July, 1196 addresses were transferred between 01:10:20 and 01:51:26 UTC time. Previously, Coldcard manufacturer Coinkite issued a security warning stating that some Coldcard Mk3 equipment generated wallet seeds might be at risk, and subsequently extended the impact to some Mk4, Mk5 and Coldcard Q solidware versions and issued emergency solidware updates. The Coinkite CEO Rodolfo Novak (NVK) apologizes for this and states that the company bears full responsibility for this solid gap. He also warned that the AI Auxiliary Code review might identify potential loopholes faster than the manual security review, making it easier for the attackers to exploit the security deficiencies in the open code. According to Galaxy Research, a future attack on the location of Coldcard's creation is still possible, and this pattern of financial flows can only prove that the funds were diverted from the same assailant and do not fully reveal the process of exploiting the loopholes。
