NewsCryptoBitcoin Cold-Wallet Attack Spreads to 4,500 Addresses as Losses Near $89 Million

Bitcoin Cold-Wallet Attack Spreads to 4,500 Addresses as Losses Near $89 Million

Author: CryptoNewsNet·

Key Takeaways

  • Total observed losses across three attack waves reached approximately 1,367 bitcoin, valued at nearly $89 million, spread across 4,585 compromised addresses.
  • The vulnerability originates from a March 2021 Coldcard firmware build that used a predictable software randomizer for seed generation instead of the device's secure hardware randomizer.
  • The third wave shifted to smaller-value targets, stealing an average of just over 0.1 bitcoin per victim compared to nearly one full bitcoin per address in the first wave.
  • Galaxy Research confirmed each individual wave was executed by a single operator but could not determine whether all three waves were carried out by the same actor or independent attackers.
  • Users who generated wallet seeds on the affected firmware remain at risk until they transfer funds to addresses derived from uncompromised entropy sources.
Bitcoin Cold-Wallet Attack Spreads to 4,500 Addresses as Losses Near $89 Million

Bitcoin Cold-Wallet Attack Spreads to 4,500 Addresses as Losses Near $89 Million

An attacker exploiting keys generated through Coldcard hardware wallets is now draining individual wallets valued at just a few thousand dollars each, signaling a shift in tactics as the campaign enters its third day. Coldcard, manufactured by Coinkite, is a widely used bitcoin-only hardware wallet marketed for its air-gapped security model, making the compromise of its key-generation process especially significant for users who adopted the device specifically to avoid this category of risk.

Galaxy Research identified a third wave of wallet sweeps early Sunday. This latest phase saw approximately 208 bitcoin stolen from 1,912 addresses between Friday midday and Saturday morning UTC, averaging just over a tenth of a bitcoin per victim. By contrast, the initial wave detected on July 30 drained an average of close to one full bitcoin per address, removing 1,083 bitcoin from 1,196 addresses in just 41 minutes.

Observed losses across all three waves now total 1,367 bitcoin — nearly $89 million — from 4,585 addresses.

The third wave has adopted notably different operational techniques from the earlier sweeps. Rather than funneling stolen coins to a small number of shared collector addresses — a pattern that made the first two waves relatively straightforward to trace — each victim's funds are now sent to a separate destination address. Additionally, the stolen bitcoin is being parked in pay-to-witness-script-hash (P2WSH) outputs, a format capable of carrying multisignature or timelock conditions, replacing the plain single-key outputs used in previous waves.

The attacker also batched an average of six victims into each sweep during wave three, whereas the first wave targeted one wallet at a time. The latest wave scanned only the default derivation path — the standard branch of the key tree a wallet checks first — rather than testing multiple branches per seed.

Galaxy Research stated it is confident that each wave was carried out by a single operator internally but declined to link the three waves to the same actor. The firm noted that the blockchain data alone cannot distinguish whether this is the same operator rebuilding after being publicly enumerated or a second independent attacker grinding the same vulnerable key space.

The underlying vulnerability traces back to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the device's hardware randomizer. This created a bounded set of possible keys that anyone with knowledge of the flaw and sufficient computing power could reproduce offline, without ever needing physical access to a device. Random number generation failures have historically been among the most damaging classes of cryptocurrency security flaws: when the entropy behind key creation is predictable, the core cryptographic assumption that private keys cannot be reproduced collapses entirely.

Nearly three days after the first wave was detected, the sweeping has not stopped. However, the declining average haul per victim suggests that the profitable portion of the compromised key space has already been largely exhausted. Users who generated wallet seeds on the affected firmware build remain exposed until they migrate funds to addresses derived from uncompromised entropy.

Source: CryptoNewsNet