Galaxy Research mapped 1,196 Bitcoin address drains to a single sweep on July 30, moving 1,082.65 BTC, about $70.2 million at the time, out of wallets in 41 minutes. The firm ties the theft to a firmware flaw in Coldcard hardware wallets, meaning the private keys were exposed before the funds ever moved, not guessed or brute-forced afterward. A hardware wallet's entire pitch is that keys never leave the device. This one apparently let them leave quietly enough that 1,196 owners found out at the same time.
The 41-minute window is the detail worth sitting with. That is not a phishing campaign working through a target list. It is a script executing against addresses whose keys were already known, which points to a bulk compromise upstream of any individual owner's behavior, most plausibly in firmware supply chain or key generation. Coldcard's manufacturer has not published its own root-cause forensics alongside Galaxy's mapping. Until that lands, the actionable step for any holder is checking firmware version and signing history against Galaxy Research's published address list, not waiting on a vendor statement to confirm what the chain already shows.