A critical vulnerability in a March 2021 Coldcard firmware release has enabled attackers to systematically drain bitcoin from thousands of wallets. The attack, first flagged by Galaxy Research, has now expanded to 4,585 addresses, with total losses approaching $89 million.
Third Wave Targets Smaller Balances
Galaxy Research identified a third wave of sweeps early Sunday, with roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC. This wave averages just over 0.1 bitcoin per victim, a significant drop from the initial wave on July 30, which saw an average of nearly 1 bitcoin per address.
The first wave alone netted 1,083 bitcoin from 1,196 addresses in just 41 minutes. Across all three waves, attackers have now siphoned 1,367 bitcoin, worth nearly $89 million at current prices.
Evolving Attack Tactics
The latest wave shows more sophisticated techniques:
- Unique destinations: Each victim's coins are sent to separate addresses, unlike previous waves that used shared collector addresses.
- Complex outputs: Funds are parked in pay-to-witness-script-hash (P2WSH) outputs, which can carry multisignature or timelock conditions, making them harder to trace.
- Batching: An average of six victims are swept per transaction, compared to one at a time in the first wave.
- Narrower scanning: The attacker only checks the default derivation path, rather than multiple branches per seed.
Root Cause: Weak Randomness
The vulnerability stems from a March 2021 firmware update that routed seed generation to a predictable software randomizer instead of the chip's hardware random number generator. This left a bounded set of possible keys that can be reproduced offline by anyone with the disclosure and sufficient computing power.
Ongoing Threat
Despite the attack being publicly flagged, the sweeps have continued for nearly three days. The declining average haul suggests that the most profitable keys have already been drained, but the attacker persists in targeting smaller balances.
Galaxy Research believes each wave is the work of a single operator, but cannot confirm whether the same actor is behind all three waves. The blockchain does not reveal whether separate sweeps are coordinated.
Key takeaway: This incident underscores the critical importance of using hardware wallets with verified randomness and keeping firmware up to date. Users who generated keys with affected Coldcard firmware should immediately move their funds to newly generated addresses.





Comments
Join Our Community
Sign up to share your thoughts, engage with others, and become part of our growing community.
No comments yet
Be the first to share your thoughts and start the conversation!