Galaxy Research identified three suspected attack waves targeting Coldcard-generated addresses, draining 1,367 BTC ($88.6M) across 4,585 addresses.
Security & Exploits ·
On-chain analysis by Galaxy Research identified three suspected attack waves targeting Coldcard-generated Bitcoin addresses, resulting in losses totaling 1,367.05 BTC (approximately $88.6 million) distributed across 4,585 addresses. The first two waves exhibited similar transaction patterns and may have originated from the same operator, though this remains unconfirmed. The third wave differed materially in structure, suggesting either a shift in the attacker's methods or involvement by a separate actor exploiting the same vulnerable address space.
Galaxy Research's investigation relied exclusively on blockchain transaction data to identify the attack patterns. The researchers noted a critical limitation: the analysis has not independently verified whether the targeted addresses were actually generated using insufficient randomness, a potential vulnerability that could explain why they became targets.
The findings leave several questions unresolved. Whether all three waves originate from a single threat actor remains uncertain. The underlying cause of the vulnerability—whether tied to Coldcard's key generation process, user error, or another factor—has not been established from the blockchain evidence alone. Additional investigation would be needed to confirm the technical mechanism that made these addresses susceptible to compromise.