Coldcard Hack May Reach $132M As At Least 15 Attackers Target Wallets

Changelly



Coldcard-linked Bitcoin thefts may have reached 2,055 BTC, worth approximately $132 million at current prices, as multiple attackers race to drain wallets generated with vulnerable firmware.

Galaxy Research has high confidence that three major waves and 14 smaller incidents removed 1,596 BTC from roughly 7,300 addresses. A suspected fourth wave would lift the total to 2,055 BTC across more than 7,700 addresses, although Galaxy has not received enough victim reports to classify that group with the same confidence.

At Least 15 Attackers Target Remaining Wallets

Galaxy Research’s Alex Thorn now estimates that at least 15 separate attackers are exploiting Coldcard-generated seeds, replacing the earlier theory that one operator controlled the coordinated drains.

The fragmented activity complicates attribution because each attacker may use different consolidation addresses, transaction structures and spending patterns. Galaxy has asked affected users to submit addresses privately so researchers can separate victim migrations from thefts and provide cleaner information to law enforcement.

The observed total has climbed sharply from the 1,083 BTC identified after Block and Coinkite disclosed the weakness. A subsequent third suspected wave removed another 207.7294 BTC before the smaller attacker clusters and possible fourth wave expanded the estimate.

Most of the suspected stolen Bitcoin remained unmoved when Galaxy published its latest analysis, including all coins attributed to the first three major waves.

Developer Says 2025 RNG Warning Was Dismissed

Bitcoin developer James O’Beirne said he questioned Coldcard’s random-number generation during a May 2025 firmware audit, more than a year before the public disclosure.

O’Beirne traced seed generation into the libngu cryptographic library and raised concerns about whether its random function was receiving secure hardware entropy. He said Coinkite dismissed the warning on the basis that a serious defect would already have been detected. Coinkite has not publicly confirmed his account of that exchange.

Block’s later technical investigation found that affected firmware could fall back to a deterministic MicroPython generator instead of using the STM32 hardware random-number generator as intended. Mk2 and Mk3 firmware added no cryptographic entropy to that fallback, while newer models retained only 32 bits during secure-element reseeding.

Coinkite’s updated advisory covers affected Mk2, Mk3, Mk4, Mk5 and Q firmware versions and provides fixed releases for each supported model.

Wallet Migration Pushes Bitcoin Activity To 2024 High

The disclosure triggered a broad movement of Bitcoin into replacement wallets and, in some cases, centralized exchanges.

Daily active Bitcoin addresses rose from approximately 645,000 on July 30 to nearly one million on July 31, the highest level since December 2024. Transfers involving amounts below 1 BTC reached roughly 39,600 BTC as smaller holders reacted to the warning.

CryptoQuant analyst JA Maartunn separately tracked 77,402 BTC moving from older UTXO age bands after the vulnerability became public, indicating that long-dormant holders also rotated funds.

Affected users must install fixed firmware, generate a completely new seed, verify the receiving address, send a small test transaction and then migrate the remaining balance. Importing the old recovery phrase into another device does not remove the exposure.



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*