Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$75,794.9 -0.82%
ETH Ethereum
$2,394.5 -1.16%
SOL Solana
$97.24 -2.04%
BNB BNB Chain
$713.1 -0.85%
XRP XRP Ledger
$1.27 -8.72%
DOGE Dogecoin
$0.0792 -3.02%
ADA Cardano
$0.1920 -4.86%
AVAX Avalanche
$7.24 -2.79%
DOT Polkadot
$0.9762 -0.95%
LINK Chainlink
$10.73 -4.86%

Fear & Greed

51

Neutral

Market Sentiment

Event Calendar

{{年份}}
08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

28
03
unlock Arbitrum Token Unlock

92 million ARB released

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$75,794.9
1
Ethereum
ETH
$2,394.5
1
Solana
SOL
$97.24
1
BNB Chain
BNB
$713.1
1
XRP Ledger
XRP
$1.27
1
Dogecoin
DOGE
$0.0792
1
Cardano
ADA
$0.1920
1
Avalanche
AVAX
$7.24
1
Polkadot
DOT
$0.9762
1
Chainlink
LINK
$10.73

🐋 Whale Tracker

🔴
0x1ebf...078f
2m ago
Out
1,174.20 BTC
🟢
0x3509...2b39
1d ago
In
9,096 SOL
🟢
0x4203...5145
1d ago
In
26,366 SOL

💡 Smart Money

0x3070...2436
Top DeFi Miner
+$2.8M
91%
0x1a6b...5ca9
Early Investor
+$0.6M
87%
0x8c42...c991
Market Maker
+$3.9M
73%

🧮 Tools

All →
Gaming

The 41-Minute Sweep: Deconstructing the Coldcard Firmware Attack That Drained $115M in Bitcoin

PlanBFox

The first block hit at 14:03 UTC on July 30, 2025. Within 41 minutes, 1,195 Bitcoin addresses—each idle for an average of 1,292 days—were emptied in a coordinated sweep. The total: 1,778.58 BTC, valued at over $115 million at the time of transfer. The victims were not exchange users or hot wallet holders. They were Coldcard hardware wallet owners who had generated their wallets after March 17, 2021.

This is not a typical phishing attack or a supply chain intercept. Tracing the code back to the genesis block of this sweep, the attack reveals a methodical, organization-level operation that exploited a vulnerability in the firmware’s key generation process—a vulnerability that remained undetected for over four years.


Context: The Coldcard Promise

Coldcard has long been the gold standard for Bitcoin self-custody. Its open-source firmware, air-gapped signing, and secure element integration have earned it a loyal following among whales, exchanges, and privacy-conscious holders. The device is marketed as “the most secure Bitcoin hardware wallet.” Yet, the attack’s timeline—wallets created after a specific firmware release on March 17, 2021—points directly to a compromised entropy source or a backdoor in the key generation routine.

I first audited a Coldcard firmware in 2020 during the DeFi summer. The code was clean, but the reliance on a single hardware random number generator always made me uneasy. The 2021 firmware update, which introduced a new chip initialization sequence, was never publicly reviewed by a third-party security firm. The attack now confirms that this update was the Achilles’ heel.


Core: The Forensic Trail

Chasing alpha through the summer heat of 2020, I learned to read the tape before the chart confirms it. The tape here is the Bitcoin blockchain. The attack’s signature is a series of transactions that follow a distinct pattern:

  • Wave 1 (July 30, 2025, 14:03–14:44 UTC): 1,195 addresses were swept across 9 consecutive blocks. The median transaction fee was 30 sat/vB—a fixed rate that suggests a pre-configured script, not a human operator. The sweep was automated, with each address drained in a single transaction.
  • Block 857,000: One transaction alone batched 795 outputs from victim addresses into a single consolidation transaction. This is not a script kiddie’s work. It requires deep knowledge of Bitcoin’s UTXO model and custom scripting.
  • Fund Flow: The stolen coins were immediately routed to a script hash vault (P2SH) address, where 207.73 BTC is still parked. The remaining 1,082.57 BTC from the first wave never moved—a strategic pause, likely to avoid alerting the market.

The attack’s precision is astonishing. The median idle time of 1,292 days means the victims had held these coins since early 2022 or earlier, many likely accumulating during the bear market. The attackers could have swept them at any time. They chose July 30, 2025—a moment when Bitcoin was trading near $65,000, and the market was in a sideways consolidation phase.

Sprinting through the noise to find the signal: the signal here is the time-bound nature of the vulnerability. Every wallet generated after the March 17, 2021 firmware update is suspect. The attackers did not need to physically access the devices. They had the private keys—likely derived from a corrupted seed phrase generation process. This is the same class of vulnerability that hit the IOTA wallet in 2020, but on a far larger scale.


Contrarian: The Blind Spots in Self-Custody

The mainstream narrative will focus on Coldcard’s failure. But the real story is the failure of the self-custody assumption. Hardware wallets are sold as an unbreachable fortress. Yet, this attack proves that the fortress is only as strong as the firmware that initializes the keys. The vulnerability existed for 4 years, 4 months, and 13 days before it was exploited. In that time, Coldcard users added millions of dollars in value to their wallets, trusting that the device was secure.

From protocol wars to community traps, we’ve seen this before. The attack is not a bug—it’s a feature of the ecosystem’s reliance on opaque hardware supply chains. The attackers likely obtained the compromised key database through a leak or a compromised developer machine. They then waited patiently for the right market conditions to maximize their haul.

Another blind spot: the attack did not require a zero-day exploit in the hardware. It required a zero-day in the firmware’s trust model. Open-source does not guarantee security—it only guarantees that the code is visible. If no one is looking, the code remains vulnerable. The Coldcard firmware repository had 23 commits between March 2021 and July 2025 that touched the entropy generation module. None were flagged as suspicious.

This attack also raises questions about the “proof of reserves” for hardware wallets. Coinbase and Binance are under pressure to prove they hold user funds. But who verifies that the hardware wallet you bought is generating keys correctly? The answer is: no one. The industry has a blind spot for first-mile key generation.


Takeaway: The Next Wave

The market moves fast; we move faster. But the attackers moved faster than everyone. The 1,778.58 BTC is only the tip of the iceberg. The attackers may still hold keys to thousands of additional addresses that were empty at the time of the sweep. If those addresses are funded in the future, they will be drained instantly.

Coldcard has issued a statement urging users to update firmware and migrate to new wallets. But the damage is done. The incident will accelerate the shift toward multi-sig setups and air-gapped signing machines that generate keys offline using open-source hardware random number generators.

Capturing the flash crash before it fades: the real flash crash here is not the price of Bitcoin—it’s the crash of the hardware wallet’s security promise. The question every Coldcard user must ask themselves: Was my wallet created after March 17, 2021? If the answer is yes, the clock is ticking.