Coldcard Exploit Hits 4,500 Addresses as Losses Approach $89 Million
Key Takeaways
A third wave of Coldcard wallet drains has pushed total losses to nearly $89 million across 4,585 addresses. Galaxy Research identifies distinct operational shifts in the latest attack vector targeting vulnerable firmware keys.
Woofun AI reports that a persistent attacker exploiting Coldcard-generated keys is systematically draining Bitcoin wallets, with Galaxy Research identifying a third wave of sweeps. The incident highlights a critical vulnerability in hardware security, as the operator continues to extract value from compromised devices.
The latest activity, flagged early Sunday, saw 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC.
Woofun AI data shows this wave utilized pay-to-witness-script-hash outputs capable of holding multisignature or timelock conditions, a shift from previous single-key outputs. Unlike the initial attack, which processed one victim at a time, this phase batched an average of six victims per sweep while scanning only the default derivation path.
Historical context reveals the July 30 opening wave averaged close to a full coin, extracting 1,083 bitcoin from 1,196 addresses in just 41 minutes. Cumulative losses across all three waves now total 1,367 bitcoin, valued at nearly $89 million, affecting 4,585 addresses. The root cause traces to a March 2021 firmware build that routed seed generation to a predictable software randomiser instead of the hardware one, leaving a bounded set of possible keys exposed.
Galaxy maintains confidence that each wave represents a single operator but refuses to link the three distinct periods. With the sweeping continuing almost three days later, the declining average haul suggests the profitable end of that key space is already picked over.
Comments
No comments yet.