LockurBlock Digital News & Media Platform

collapse
Home / Daily News Analysis / Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million

Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million

Aug 08, 2026  Twila Rosenbaum 5 views
Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million

The ongoing attack against Bitcoin cold wallets using weak randomness from a specific Coldcard firmware release has expanded dramatically. New data from Galaxy Research indicates that a third wave of automated sweeps has pushed the total number of affected addresses to 4,585, while cumulative losses have climbed to roughly 1,367 bitcoin—worth approximately $89 million at current market prices.

The Vulnerability

This incident traces back to a vulnerability in a March 2021 firmware release from Coldcard, a hardware wallet manufactured by Coinkite. The device is widely regarded as one of the most secure Bitcoin storage options, given its focus on air-gapped operations and user-controlled entropy. However, the weak randomness in that particular firmware allowed attackers to reconstruct private keys for wallets that were generated using the flawed software. By understanding the patterns in the random number generator, the attackers could produce matching keys and drain balances.

The vulnerability is classified as a key-space reduction issue. In correctly designed hardware wallets, the private keys are derived from a high-quality source of randomness, meaning the potential key space is astronomical. But in the affected firmware version, the entropy source was far weaker than expected. This meant that only a limited number of possible private keys could be generated. An attacker who knew the algorithm and the seed could brute-force the key space and find the exact private keys for wallets created during the affected period.

This type of attack is more commonly associated with poorly implemented software wallets, where insufficient entropy from system clocks or other predictable sources has led to funds being stolen. Seeing it target a hardware wallet is rare and alarming, as these devices are supposed to offer institutional-grade security. The fact that a firmware bug could undermine this trust has sent ripples through the Bitcoin community.

The Three Waves

Galaxy Research analysts have been monitoring the situation since the first suspicious sweeps were observed. They have now identified three distinct waves of attacks. The initial waves appeared to target high-value accounts with substantial bitcoin balances, likely to maximize the payoff from each compromised key. The third wave, however, shows a noticeable shift in behavior. Instead of going after large holdings, the attacker is now sweeping smaller balances, likely to avoid detection and to build a broader web of compromised addresses.

The address count of 4,585 is a stark indicator of how widespread the attack has become. Each address represents a Bitcoin wallet that has been fully drained, and while one user may control multiple addresses, the loss touches a significant number of individuals. The fact that the attacker is still active and evolving suggests that the underlying vulnerability has not been fully eliminated, or that the attackers have stockpiled enough compromised keys to continue for some time.

Changing Tactics

In the latest wave, the transaction structures are more complex than in earlier sweeps. Funds are being routed through intermediaries, and some transactions show signs of being passed through mixing services or privacy-enhancing tools in an attempt to obscure the final destination. This marks a deliberate shift in operational security. The attacker appears to be learning from previous patterns and adapting to avoid blockchain analytics.

Targeting smaller balances also makes tactical sense. Smaller amounts are less likely to trigger immediate alarm or legal action from individual victims. It also reduces the chance that exchanges will flag the incoming funds as suspicious, since the transactions can be broken into smaller chunks. This move toward micro-sweeping suggests a long-term, patient operation designed to fly under the radar while steadily extracting value from vulnerable wallets.

Single Operator or Multiple?

One of the central questions is whether the same entity is behind all three waves. Galaxy Research believes that each wave individually appears to be the work of a single operator. The blockchain patterns, the timing of transactions, and the choice of addresses point to an automated system controlled by one party per wave. However, there is no definitive way to prove that the same person or group orchestrated all three campaigns.

The blockchain does not reveal the identity of the actors, nor does it show whether separate sweeps are coordinated. It is entirely possible that the attacker is one individual who has changed tactics over time, refining their methods with each wave. Alternatively, the success of the first waves could have inspired copycat attacks by other malicious actors. Galaxy Research acknowledges this uncertainty, noting that without off-chain intelligence, the true number of perpetrators may remain unknown.

Despite this, the consistent pattern of exploiting the same Coldcard-related vulnerability strongly suggests a common origin. If different actors were involved, they would likely have focused on different wallet types or used different attack vectors. The fact that all three waves exploit the same weak randomness issue indicates that the primary operator, or an organized group, controls the compromised key database.

Impact on the Ecosystem

The attack has wider implications for the Bitcoin ecosystem. It serves as a reminder that no wallet is immune to implementation bugs. Even devices designed to be bulletproof can suffer from software flaws that allow attackers to bypass the security model. It also highlights the dangers of using any randomness source that is not properly seeded with enough entropy. Coldcard has since released patches, but the affected keys remain vulnerable, meaning any user who hasn't migrated their funds is still at risk.

The cumulative loss of $89 million is substantial, but perhaps more important is the psychological impact. Many Bitcoin users choose hardware wallets specifically to protect themselves from remote attacks. When a hardware wallet vendor is affected by a vulnerability, it shakes confidence in the entire sector. However, it is important to put the attack in perspective. The number of affected addresses is a small fraction of the total number of Bitcoin wallets in use. And the loss is concentrated among users who did not update their firmware or who generated keys during a specific time window.

Still, this incident will likely prompt hardware wallet manufacturers to be even more rigorous in their entropy generation and to audit their code more thoroughly. It also contributes to the growing call for more transparent security disclosures and faster firmware update rollouts. The Bitcoin community will be watching closely to see how Coinkite and other vendors respond to this challenge.

What Should Users Do?

Users who own a Coldcard and suspect they might be affected should check their wallet generation history. If they used firmware from March 2021, they should assume their keys are compromised. The safe course of action is to create a new wallet on the latest firmware and transfer all funds there. It is also advisable to generate the seed using a hardware random number generator or dice rolls, rather than relying solely on the device's internal RNG.

Exchanges and custodial services are also on alert. They can monitor incoming deposits for signs of the stolen funds. However, given the attacker's attempts to obfuscate the trail, this is difficult. Some exchanges have taken proactive measures by blacklisting known attacker addresses and freezing funds that match specific transaction patterns. Yet the attacker's evolving tactics may render some of these measures ineffective over time.

For ordinary Bitcoin users, the lesson is clear: security is not a one-time purchase. Firmware updates exist for a reason, and ignoring them can have severe consequences. Coldcard users who have not updated their devices since early 2021 should treat their wallets as compromised, even if no funds have been taken yet. The attack may still be in progress, and the attacker could be waiting to strike.

Ongoing Monitoring

Galaxy Research says it will continue to track the address sets and transaction flows associated with the attack. The latest wave indicates that the attacker is still active and refining their methods. It is unclear whether further waves will follow or whether the current campaign will fade out as the vulnerable key space is exhausted. Analysts are also watching for any signs that the stolen funds are being laundered through major exchanges or converted into other assets.

The broader lesson is that randomness is a critical component of cryptocurrency security. Bitcoin's private keys are simply numbers, and if the number generation process is biased, the entire system is at risk. This incident will likely become a case study in how a single firmware bug can lead to millions of dollars in losses, and it reinforces the importance of using externally validated randomness sources when creating wallet seeds.

As the attack continues to unfold, the Bitcoin community is left to grapple with the reality that even the most trusted hardware can have hidden flaws. The only reliable defense is vigilance: keep firmware up to date, generate keys with verified randomness, and never assume that a device is secure just because it is touted as a hardware wallet.


Source:Coindesk News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy