Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

Binance
BTCC



In brief

  • The Coldcard exploit is ongoing, with Galaxy Research now tracking about $88.6 million stolen across 4,585 addresses in three waves.
  • Galaxy’s Alex Thorn described the sweeps as deliberate and likely LLM-orchestrated, warning that every single-sig Coldcard address created after the March 2021 firmware flaw will eventually be drained.
  • The breach has spurred an unusual reversal of the “not your keys, not your coins” ethos as users move Bitcoin back to exchanges.

The theft of Bitcoin from compromised Coldcard hardware wallets is still underway, with researchers now tracking losses of roughly $88 million and warning that every vulnerable device will eventually be emptied.

Galaxy Research said Saturday it has identified a third wave of thefts, in which 207.73 BTC was drained, lifting its observed tally to about 1,367 BTC—around $88.6 million—across 4,585 addresses. The firm called the exploit ongoing and urged anyone holding single-signature funds on a Coldcard to move them at once. Galaxy said it has flagged roughly 600 suspected attacker addresses to federal investigators, compliance firms and cross-industry cyber investigators, crediting victims who shared transaction details for helping map the on-chain patterns.

“I continue to investigate and add new Coldcard victim and attacker addresses to our investigation database,” Galaxy’s head of research Alex Thorn posted to X. “The attack is ongoing—move your funds off Coldcard-generated addresses immediately if you have not done so.”

okex

The flaw, as Decrypt previously reported, stems from a March 2021 firmware build error on Coinkite’s devices that caused seed phrases to be generated with far too little randomness, leaving private keys guessable. Thorn wrote that the sweeps look deliberate and programmatic, probably orchestrated with a large language model, and cautioned that every single-sig Coldcard address created after that 2021 update will eventually be drained, saying it is only a matter of time.

Thorn noted the stolen coins had sat untouched for years before being taken—an average dormancy of 3.18 years—underscoring that the victims were long-term holders. The funds from the three documented waves remain parked in attacker addresses and have not moved.

The fallout has driven a panicked response from affected users, with security experts urging caution when moving funds to new addresses. Many of the affected users are racing to move Bitcoin off self-custody and back onto centralized crypto exchanges, such as Coinbase or Binance, or freshly generated addresses—an inversion of the industry’s usual “not your keys, not your coins” ethos.

For some, the warnings came too late. Canadian coach Jonathan Goodman said in a post on X that 18.25 BTC, worth about $1.6 million Canadian, was swept from his wallets in a seven-minute span on July 29, despite his keys sitting in a safety deposit box that never touched the internet. “Perhaps the hardest part about this is that I did everything right,” he wrote, adding that he is filing reports with police and the Ontario Securities Commission.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.





Source link

Bybit

Be the first to comment

Leave a Reply

Your email address will not be published.


*