Fourth Coldcard Sweep Wave Hits $114M as Firmware Flaw Exposed
Key Takeaways
A fourth wave of Coldcard wallet exploits has emerged, potentially raising total losses to $114 million. Researchers identify a firmware flaw from March 2021 allowing predictable seed generation, urging users to move funds immediately.
Woofun AI reports that a fourth wave of Bitcoin (BTC) address sweeps targeting Coldcard cold wallets initiated early Monday, with Alex Thorn of Galaxy Research identifying the active threat on July 30. The ongoing incident highlights a critical vulnerability in devices manufactured by Coinkite, exposing users to immediate financial risk as attackers exploit predictable key generation.
The attack mechanism relies on the replace-by-fee feature within the Bitcoin network, allowing attackers to overwrite pending transactions with higher fees. Victims can mitigate this by monitoring the mempool for unconfirmed transactions and paying a higher fee to move coins before confirmation. This race condition leaves funds vulnerable until the transaction is finalized in a block.
Per Woofun AI, the root cause stems from a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the hardware one. This flaw made keys reproducible offline, prompting Coinkite to release emergency firmware and urge users to migrate funds to a fresh one. The vulnerability specifically affects single-key seeds, leaving multisignature setups untouched.
Statistical analysis reveals the initial wave on July 30 drained 1,083 bitcoin from 1,196 addresses in 41 minutes, while two subsequent weekend waves added 1,367 bitcoin across 4,585 addresses. The cumulative impact across four waves reached 1,816 bitcoin, valued near $114 million, affecting over 5,200 addresses. Activity between blocks 960,778 and 960,792 showed 218 transactions hitting 462 victim addresses at 14 sweeps per block, a rate 45 times the normal 0.3 baseline. While earlier waves used shared collectors, this phase utilized six destination addresses with prior history, distinguishing them from fresh addresses.
Thorn’s methodology relied on pattern matching rather than direct victim report, prioritizing speed over confirmation to issue warnings. Users are advised to check funds, move anything off affected devices, and bid the fee up to secure their assets.
Comments
No comments yet.