LostYourMojo

Market Prices

BTC Bitcoin
$78,249.3 +0.71%
ETH Ethereum
$2,457.45 +0.77%
SOL Solana
$105.74 +2.27%
BNB BNB Chain
$693.3 +0.55%
XRP XRP Ledger
$1.4 +1.20%
DOGE Dogecoin
$0.0854 +0.84%
ADA Cardano
$0.2020 -0.20%
AVAX Avalanche
$7.33 +0.66%
DOT Polkadot
$0.8436 -0.18%
LINK Chainlink
$11.46 +0.37%

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$78,249.3
1
Ethereum ETH
$2,457.45
1
Solana SOL
$105.74
1
BNB Chain BNB
$693.3
1
XRP Ledger XRP
$1.4
1
Dogecoin DOGE
$0.0854
1
Cardano ADA
$0.2020
1
Avalanche AVAX
$7.33
1
Polkadot DOT
$0.8436
1
Chainlink LINK
$11.46

🐋 Whale Tracker

🔴
0x9e9d...dd8c
12m ago
Out
235,285 USDT
🔵
0xb833...ebaa
6h ago
Stake
1,514,552 USDT
🔵
0x13fa...ec65
3h ago
Stake
17,393 BNB

Coldcard’s $115 Million Heist: How a 2021 Firmware Flaw Became a 2025 Liquidation Cascade

CryptoSam GameFi
I trace the wallet, not the whisper. On July 30, 2025, a series of transactions began sweeping Bitcoin addresses with surgical precision. Over 41 minutes, 1,195 addresses were drained in a single block window—9 blocks, 133 transactions per block. The victims weren’t exchange hot wallets or DeFi contracts. They were Coldcard hardware wallet users, holders of the gold standard in Bitcoin self-custody. The total: 1,778.58 BTC, or $115 million at current prices. The attack’s signature? A time-aligned vulnerability: every affected address generated a wallet after March 17, 2021—the date of a specific Coldcard firmware release. The median idle time of those addresses was 1,292 days, meaning the attacker waited over three years to strike. This isn’t a hack. It’s a forensic indictment of the hardware wallet industry’s failure to enforce verifiable randomness and firmware integrity. Coldcard is the titanium fortress of the Bitcoin maximalist crowd—a hardware wallet that prides itself on air-gapped security, open-source transparency, and physical attack resistance. Manufactured by Coinkite, it has been marketed as the only device that can withstand even a $5 wrench attack. The incident in question, first reported by Galaxy Research, targets a specific vulnerability window: firmware versions released on or after March 17, 2021. The attacker didn’t physically steal the units or intercept delivery. They exploited a flaw in the key generation process—likely a compromised entropy source or a backdoor in the random number generator. The timing is damning: the attack only affects wallets created after that firmware date, and the assets were swept in a coordinated wave starting July 30, 2025. The victims include individuals who likely believed their funds were safe from any remote attack. The core of this investigation is the on-chain data. The attacker operated in three waves. Wave 1: 1,195 addresses drained in 41 minutes, using a fixed 30 sat/vB fee—a sign of automation, not panic. Wave 2: a single transaction consolidating 795 addresses into one output. Wave 3: the remaining 207.73 BTC moved into a script hash vault, a Bitcoin script-based smart contract that requires a specific spending condition. This is not a script kiddie operation. The attacker used batch transaction construction, script hash vaults, and a precise timing mechanism that suggests months of preparation. The median idle time of 1,292 days between wallet creation and theft indicates the attacker either acquired the private keys recently or waited for the addresses to accumulate value. The latter is more likely: the longer the wait, the higher the potential reward. This is a classic supply-chain attack, but the supply chain is the firmware itself. From my experience auditing the 0x protocol’s signature malleability flaw in 2018, I learned that the most dangerous vulnerabilities are those that leave no trace until the trigger. In that case, the developers dismissed my report until the proof-of-concept code forced a patch. Here, the attack vector is even more insidious because the user cannot detect it. The victim’s wallet appears normal, the private key is generated on the device, and the funds remain untouched for years. Only when the attacker decides to sweep do the victims realize their security was an illusion. The attack’s technical execution is a masterclass in operational security. The funds were not mixed immediately; over 1,082 BTC remained in the initial swept addresses, suggesting either a deliberate slow exit or a confidence that the wallets cannot be traced back to the attacker. The use of a script hash vault for the final tranche indicates a desire to lock the funds behind a script that may require a future action—perhaps to delay liquidation or to create a smart contract that distributes to multiple recipients. The contrarian angle: the bulls might argue that this attack is limited to a specific firmware version and that Coldcard users who updated or who used older firmware are safe. They might also point out that the attacker’s method is not a 0-day exploit but a “feature” of the hardware’s design—the randomness source could be compromised by a state-level actor or a malicious insider. In fact, the attacker’s behavior suggests a high level of patience and discipline, which could be interpreted as a sign of a sophisticated intelligence operation rather than a common thief. The bulls might also note that the attack was first detected by Galaxy Research, not by Coldcard’s own security team, which raises questions about the industry’s monitoring capabilities. However, the bulls miss the larger point: this attack exposes the fragility of the entire hardware wallet ecosystem. If a single firmware release can compromise the key generation of all subsequent wallets, then the security model of “trust the device” is inherently flawed. The attacker didn’t need to physically access the devices; they only needed to corrupt the firmware update process. This is a systemic failure of the supply chain, not a user error. The takeaway is clear: hardware wallets are not immune to the same vulnerabilities that plague DeFi protocols. The industry’s obsession with physical security has blinded it to the software attack surface. The cold wallet is only as cold as the firmware that generates its keys. Until hardware manufacturers implement verifiable, user-auditable key generation—such as using a reproducible seed from a trusted source like a hardware random number generator that can be tested offline—users are trusting a black box. The attack on Coldcard is a wake-up call for the Bitcoin maximalist community: hype is the only asset in a vacuum mint. When the yield is too high, the exit is rigged. In this case, the yield was the false sense of security, and the exit was a 41-minute sweep. The question now is: how many other wallets are sitting on that same firmware, waiting for the attacker to decide it’s time to cash in?

Fear & Greed

68

Greed

Market Sentiment

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x32ae...08a8
Early Investor
+$3.3M
68%
0x8652...f535
Institutional Custody
-$3.5M
76%
0x7e9f...4a8e
Top DeFi Miner
+$3.0M
71%