Coldcard Bitcoin wallet exploit expands to $88M in losses across 4,585 addresses as attackers continue draining funds in a third wave.
Security & Exploits ·
A third wave of thefts from Coldcard hardware wallets has pushed total losses to approximately $88.6 million across 4,585 addresses, according to Galaxy Research. The latest round involved 207.73 BTC drained from affected users, bringing cumulative theft to roughly 1,367 BTC. Galaxy's head of research flagged about 600 suspected attacker addresses to federal investigators and compliance firms, urging owners of single-signature Coldcard funds to relocate assets immediately.
The vulnerability traces to a March 2021 firmware error on Coinkite's devices that generated seed phrases with insufficient randomness, making private keys mathematically predictable. Researchers characterize the draining pattern as deliberate and programmatic, potentially orchestrated through large language models. Notably, the stolen coins had remained dormant for an average of 3.18 years before being swept, indicating that victims were long-term holders unaware their keys had been compromised.
The incident has triggered an unusual behavioral shift: affected users are moving Bitcoin from self-custody back to centralized exchanges like Coinbase and Binance—inverting the crypto industry's standard "not your keys, not your coins" messaging. Galaxy cautioned that every single-signature address generated after the vulnerable 2021 update will eventually be emptied, though the timing and scope of remaining waves remain unclear. Stolen funds remain in attacker addresses with no outbound movement yet observed.