Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million
Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

AI-assisted summary based on the linked source. Verify market-moving details at the original publisher before acting.
A vulnerability originating from a March 2021 Coldcard hardware wallet firmware release has allowed attackers to systematically steal bitcoin from thousands of wallets. This flaw involved the use of a predictable software-based random number generator for seed creation instead of the device’s intended hardware randomizer. As a result, attackers have been able to reproduce private keys offline without needing physical access to the wallets.
According to research by Galaxy Research, there have been three distinct waves of attacks exploiting this vulnerability. Collectively, the attacks have drained approximately 1,367 bitcoin, equivalent to nearly $89 million at recent market prices, from 4,585 unique addresses. The initial wave, occurring on July 30, swept 1,083 bitcoin from about 1,196 addresses in just 41 minutes. The most recent wave, identified early on August 1, targeted many smaller wallets and moved roughly 208 bitcoin from 1,912 addresses.
Galaxy Research notes that each of the three waves appears to be internally coordinated by a single operator, though it cannot confirm whether one actor is responsible for all three waves due to limitations in blockchain data. The strategies in the latest wave differed by using more complex transaction patterns, sending stolen coins to unique destinations rather than shared collector addresses, and batching multiple victims per transaction instead of handling one at a time. This shift led to greater difficulties in tracing the funds.
The ongoing activity indicates that the attackers are still working through the vulnerable key space, but the decreasing average amount stolen per wallet suggests that the most profitable targets may have already been compromised. Galaxy Research highlights the seriousness of this flaw because it compromises the security of a broad set of Coldcard wallets generated with this specific flawed firmware, emphasizing the risks posed by predictable randomness in cryptographic key generation.