Galaxy Research has reconstructed a sweeping Coldcard hardware wallet compromise that lasted about 40 minutes and ultimately traced more than 1,000 Bitcoin, worth roughly $70 million, stolen from 1,196 addresses. This is not the seed phrase slip-up talked about previously. It’s broader. The chain of events points to a seed-generation weakness inside Coldcard firmware, creating risk that affected users across many years of wallet creation.

Most of the damage landed in a tightly coordinated drain on July 30, 2026. Early reports put the theft closer to 594 Bitcoin from about 500 wallets. The newer forensic tracing ties the wider drain to 1,196 addresses and more than 1,000 Bitcoin, showing that what first looked smaller was part of a much broader compromise.

Coinkite, which makes Coldcard, warned users about affected firmware. The key question now is how fully the exposure has been mapped and whether every affected wallet has already been identified. For hardware wallet users and makers, this incident shifts the conversation: device trust is not just about personal operational security, but also about hidden risk accumulating in firmware over time.