Series of three attacks on Coldcard wallet addresses compromised 4,585 wallets and stole 1,367.05 BTC.
Security & Exploits ·
Galaxy Research identified three waves of attacks targeting addresses generated by Coldcard wallets, with a combined total of approximately 1,367.05 BTC stolen across 4,585 addresses. The third wave, identified most recently, involved the draining of 207.7294 BTC. All cryptocurrency taken across the three waves remains held unspent in attacker-controlled addresses.
The analysis found that Waves 1 and 2 followed similar patterns—including identical funnel topology, shared collector addresses, and timing 27 hours apart—suggesting a single operator in each case. Wave 3 diverged significantly on multiple behavioral dimensions: it abandoned shared collectors for one destination per victim, held funds in a different format, batched multiple victims into single transactions, and targeted only the default derivation path. The vulnerable Coldcard firmware was shipped on March 17, 2021, and none of the compromised coins were created before that date.
Galaxy Research emphasized that its findings rest on blockchain analysis alone and has not computationally verified whether identified addresses were generated with low entropy. While Waves 1 and 2 appear linked by pattern similarity, no definitive connection exists between those waves and Wave 3; the third wave may represent a separate actor exploiting the same vulnerability independently. All attacker addresses remain unspent on-chain, and the researchers cautioned their analysis should not be considered complete or definitive.