Bitcoin Cold-Wallet Attack Escalates: 4,500+ Addresses Drained, Losses Near $89M
Coindesk•5 hours ago•
990

Bitcoin Cold-Wallet Attack Escalates: 4,500+ Addresses Drained, Losses Near $89M

Technology
bitcoin
coldcard
security
vulnerability
cryptocurrency
Share this content:

Summary:

  • 4,585 Bitcoin addresses have been drained across three attack waves, with total losses nearing $89 million.

  • The third wave targets smaller balances, averaging just 0.1 BTC per victim, and uses more complex transaction patterns to evade tracking.

  • The attack exploits a March 2021 Coldcard firmware vulnerability that used a predictable software randomizer for seed generation.

  • Galaxy Research believes each wave is the work of a single operator, but cannot determine if all three are linked.

  • Affected users are urged to move funds immediately to newly generated addresses.

A critical vulnerability in a March 2021 Coldcard firmware release has enabled attackers to systematically drain bitcoin from thousands of wallets. The attack, first flagged by Galaxy Research, has now expanded to 4,585 addresses, with total losses approaching $89 million.

Third Wave Targets Smaller Balances

Galaxy Research identified a third wave of sweeps early Sunday, with roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC. This wave averages just over 0.1 bitcoin per victim, a significant drop from the initial wave on July 30, which saw an average of nearly 1 bitcoin per address.

The first wave alone netted 1,083 bitcoin from 1,196 addresses in just 41 minutes. Across all three waves, attackers have now siphoned 1,367 bitcoin, worth nearly $89 million at current prices.

Evolving Attack Tactics

The latest wave shows more sophisticated techniques:

  • Unique destinations: Each victim's coins are sent to separate addresses, unlike previous waves that used shared collector addresses.
  • Complex outputs: Funds are parked in pay-to-witness-script-hash (P2WSH) outputs, which can carry multisignature or timelock conditions, making them harder to trace.
  • Batching: An average of six victims are swept per transaction, compared to one at a time in the first wave.
  • Narrower scanning: The attacker only checks the default derivation path, rather than multiple branches per seed.

Root Cause: Weak Randomness

The vulnerability stems from a March 2021 firmware update that routed seed generation to a predictable software randomizer instead of the chip's hardware random number generator. This left a bounded set of possible keys that can be reproduced offline by anyone with the disclosure and sufficient computing power.

Ongoing Threat

Despite the attack being publicly flagged, the sweeps have continued for nearly three days. The declining average haul suggests that the most profitable keys have already been drained, but the attacker persists in targeting smaller balances.

Galaxy Research believes each wave is the work of a single operator, but cannot confirm whether the same actor is behind all three waves. The blockchain does not reveal whether separate sweeps are coordinated.

Key takeaway: This incident underscores the critical importance of using hardware wallets with verified randomness and keeping firmware up to date. Users who generated keys with affected Coldcard firmware should immediately move their funds to newly generated addresses.

Comments

0

Join Our Community

Sign up to share your thoughts, engage with others, and become part of our growing community.

No comments yet

Be the first to share your thoughts and start the conversation!

Newsletter

Subscribe our newsletter to receive our daily digested news

Join our newsletter and get the latest updates delivered straight to your inbox.

BitcoinToday.app logo

BitcoinToday.app

Get BitcoinToday.app on your phone!