
More than 1,196 Bitcoin wallets were drained of approximately 1,082 BTC worth $70.2 million around 30 hours before a Coldcard Mk3 vulnerability was publicly disclosed, according to Galaxy Research.
Key Takeaways
- Approximately 1,082.65 BTC, valued at around $70.2 million, was stolen.
- The funds were drained from 1,196 Bitcoin wallets.
- The incident reportedly occurred 30 hours before a Coldcard Mk3 vulnerability became public.
- Galaxy Research says the stolen Bitcoin was consolidated into four collector addresses within 41 minutes.
- As of the latest analysis, nearly all of the stolen Bitcoin remains unspent.
A Sophisticated Bitcoin Theft Raises Serious Security Questions
A large-scale Bitcoin theft has drawn attention across the cryptocurrency industry after blockchain researchers discovered that 1,196 Bitcoin wallets were emptied approximately 30 hours before a security vulnerability affecting the Coldcard Mk3 hardware wallet was publicly disclosed.
According to Galaxy Research, the attackers stole 1,082.65 BTC, worth roughly $70.2 million, before rapidly consolidating the funds into just four Bitcoin addresses.
The timing of the theft has raised significant questions about whether the attackers had prior knowledge of the vulnerability or exploited an undisclosed weakness before security researchers publicly revealed it.
At this stage, investigators have not confirmed how the compromise occurred, and no official attribution has been made.


Coldcard hardware wallet and blockchain transaction analysis.
What Galaxy Research Found
Blockchain analysis published by Galaxy Research shows that the theft unfolded with remarkable speed.
According to the firm’s data:
- 1,196 wallet addresses were completely emptied.
- A total of 1,082.65 BTC was transferred.
- The attackers completed the operation in approximately 41 minutes.
- The Bitcoin was consolidated into four primary collector wallets.
- Nearly 100% of the stolen funds remain unspent at the time of analysis.
The report also notes that most of the affected wallets used native SegWit (BIP-84) addresses, while a smaller number consisted of nested SegWit (BIP-49) and legacy Bitcoin addresses.
The rapid movement of funds suggests the attackers executed a highly coordinated operation rather than a random series of isolated wallet compromises.
Why the Timing Matters
Perhaps the most concerning aspect of the incident is its timing.
Galaxy’s analysis indicates the wallets were drained roughly 30 hours before details of the Coldcard Mk3 vulnerability became public.
That sequence has prompted speculation that the attackers may have:
- Discovered the vulnerability independently.
- Gained early knowledge before public disclosure.
- Exploited another weakness unrelated to the published vulnerability.
At present, investigators have not confirmed which explanation is correct, and the available blockchain evidence alone cannot determine how the attackers gained access to the wallets.

Digital forensic investigation into a large Bitcoin theft.
Could the Bitcoin Still Be Recovered?
One notable finding from Galaxy’s report is that the stolen Bitcoin has not yet been widely distributed.
Instead, nearly all of the funds remain consolidated in a handful of addresses.
While Bitcoin transactions cannot be reversed, investigators and blockchain analytics firms can continuously monitor the movement of these coins.
If the attackers eventually attempt to move the funds through exchanges, mixing services, or cross-chain bridges, those transactions could provide additional clues for investigators and potentially trigger compliance actions by regulated platforms.
What Hardware Wallet Users Should Do
Although the investigation remains ongoing, security experts generally recommend that hardware wallet users:
- Ensure wallet firmware is updated to the latest version.
- Verify firmware updates only through official manufacturer sources.
- Never enter recovery seed phrases into websites or unknown software.
- Monitor official security advisories from wallet manufacturers.
- Transfer funds to a newly generated wallet if a confirmed vulnerability affects their device.
Users should avoid acting on rumors or unverified social media claims until wallet manufacturers publish official guidance.
Conclusion
The theft of 1,082.65 BTC from 1,196 Bitcoin wallets represents one of the most significant wallet-draining incidents reported this year. The fact that the attack occurred approximately 30 hours before the disclosure of a Coldcard Mk3 vulnerability has intensified scrutiny over the incident, although investigators have not established a confirmed link between the exploit and the vulnerability.
With nearly all of the stolen Bitcoin still sitting in a small number of wallets, blockchain investigators will continue tracking the funds as the industry awaits further findings from security researchers and wallet developers.


