A Coldcard firmware bug from March 2021 has let one or more attackers reproduce weak, predictably generated keys and drain thousands of bitcoin wallets. Three separate waves have now swept 1,367 bitcoin — nearly $89 million — from 4,585 addresses, and the draining has not stopped.
A flaw in Coldcard hardware wallets has let one or more attackers drain bitcoin from thousands of victims. Losses have now reached 1,367 bitcoin — nearly $89 million — from 4,585 addresses across three separate sweeps. The sweeping has continued for almost three days since it began, and the falling average haul suggests the profitable end of the exposed key space is already picked over.
Third wave targets smaller wallets
Galaxy Research flagged a third wave of sweeps early Sunday, draining roughly 208 bitcoin from 1,912 addresses between Friday midday and Saturday morning UTC. That works out to just over a tenth of a bitcoin per victim, far below the payouts in the opening wave.
By contrast, the July 30 opening wave averaged close to a full coin, pulling 1,083 bitcoin from 1,196 addresses in 41 minutes. Total losses across all three waves now stand at 1,367 bitcoin, nearly $89 million, from 4,585 addresses.
Attacker changes how funds move onchain
Wave three sends each victim's coins to its own destination rather than the handful of shared collector addresses that made the first two waves easy to map. It parks the funds in pay-to-witness-script-hash outputs, a format that can carry multisignature or timelock conditions, instead of the plain single-key outputs used before.
This wave also batched an average of six victims into each sweep, where wave one took exactly one at a time. It scanned only the default derivation path instead of testing several branches per seed.
One operator per wave, no confirmed link
Galaxy Research is confident each wave is internally the work of a single operator, but it will not link the three waves together, since the blockchain does not reveal whether separate sweeps are coordinated. The flaw traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the chip's hardware one, leaving a bounded set of keys that anyone with the disclosure and enough compute can reproduce offline.
Source: CoinDesk
Trading involves risk.