Losses tied to the ColdCard hardware wallet vulnerability have climbed to nearly $89 million with attackers expanding the campaign to 4,585 Bitcoin addresses across three waves of coordinated thefts, according to Galaxy Research.

The latest sweep brings the total stolen to 1,367 BTC, up from roughly 1,083 BTC ($70 million) reported a day earlier.

The attack first emerged on July 30 when hackers drained about 594 BTC from nearly 500 wallets in what initially appeared to be an isolated incident. Hours later, a much larger second wave swept more than 1,196 wallets, pushing losses past $70 million and revealing that the exploit was targeting wallets created with vulnerable versions of Coldcard firmware rather than compromising the devices themselves.

 

BITCOIN | ~500 Bitcoin Hardware Wallet Addresses Get Drained of ~$40 Million

 

The newly identified third wave suggests the campaign is still evolving.

Unlike the earlier attacks which consolidated stolen bitcoin into a handful of collector wallets, the latest operation sends funds from each victim to separate destination addresses and stores them in pay-to-witness-script-hash (P2WSH) outputs, a more sophisticated approach that may complicate blockchain analysis.

Researchers say the exploit stems from a firmware build configuration that caused affected Coldcard devices to generate wallet seeds using predictable hardware values instead of the device’s dedicated hardware random-number generator. Because every Bitcoin private key is derived from that seed, attackers who can recreate it can derive the same wallet and sweep funds without ever touching the physical device.

 

The incident has become one of the largest attacks ever targeting Bitcoin self-custody through cryptographic key generation rather than malware, phishing or exchange breaches. It has also highlighted a unique supply-chain risk:

users who securely stored offline wallets for years remained vulnerable if the wallet was originally created with the affected firmware, regardless of whether the device was later updated.

 

Galaxy Research warns that the growing number of affected addresses indicates attackers are continuing to identify vulnerable wallets suggesting the total losses could rise further as additional weak seeds are reconstructed and exploited.

 

 

 

CASE STUDY | Why This Cold Wallet Exploit Exposes a Big Bitcoin Hardware Security Vulnerability

 

 

 

 

Stay tuned to BitKE on crypto developments globally. 

Join our WhatsApp channel here.

Follow us on X for the latest posts and updates

Join and interact with our Telegram community

__________________