Coldcard wallet exploit reaches 4,585 addresses in third attack wave
Security & Exploits ·
Galaxy Research says a newly identified sweep brings total losses tied to compromised Coldcard-generated addresses to 1,367.05 BTC, worth roughly $88.6 million.
A third wave of address sweeps linked to the Coldcard hardware wallet has pushed the scale of the exploit to 4,585 compromised addresses and 1,367.05 BTC drained, according to an analysis from Galaxy Research. The newest wave alone accounted for 207.7294 BTC, following an earlier disclosure that identified 1,158.81 BTC taken from 2,673 addresses in a second wave, funds that remain sitting across seven attacker-controlled addresses. Separate coverage from Decrypt puts the combined losses at roughly $88 million and notes the draining activity is ongoing.
Galaxy Research cautions that its findings rest entirely on parsing Bitcoin's public block data and the unspent-transaction-output set, not on confirmation that flagged addresses were actually generated with low entropy; some starting points came from victims who posted on X. The researchers describe the first two waves as sharing a common structure — the same funnel into a small set of collector addresses, the same P2WPKH output type, overlapping derivation paths, and a roughly 27-hour gap between them — though they stop short of calling it proof of a single operator, pointing to differences in fee behavior and use of replace-by-fee signaling.
The third wave breaks from that pattern almost entirely. Rather than routing funds to shared collector addresses, it sends each victim's coins to its own destination, uses P2WSH instead of P2WPKH, bundles an average of 6.37 victims per sweep transaction (compared with exactly one in the first wave), and only checks the default derivation path. Galaxy Research says this could reflect the same attacker operating retooled software to resist clustering analysis, or a separate actor exploiting the same underlying weakness independently — a possibility the researchers say is plausible given that details of the vulnerability have already been made public.
All of the roughly 1,366.3865 BTC now sitting in attacker-controlled addresses remains unspent on-chain. By count, most affected addresses held under 1 BTC, though total value skews toward larger balances, a pattern Galaxy Research says looks more like individual self-custody than institutional holdings. Every coin identified across the three waves traces back to Coldcard firmware that shipped on March 17, 2021, near block 674951, with no stolen funds predating that block.
What remains unresolved is whether the three waves originate from one attacker or more than one working the same vulnerable key space, a question Galaxy Research says on-chain data alone c