🚨 $89 MILLION GONE. NOT FROM A BITCOIN HACK—FROM HUMAN NEGLIGENCE.
Stop calling this a "Bitcoin hack." Bitcoin wasn't hacked.
People were.
A catastrophic security failure linked to vulnerable Coldcard-generated wallet seeds has now escalated into one of the largest wallet-draining campaigns in recent memory.
The Numbers Are Brutal
- 1,367 BTC stolen
- Nearly $89 million lost
- 4,585 victim addresses compromised
- Attack still ongoing
According to Galaxy Research, this is now the third wave of coordinated wallet sweeps.
The first wave was devastating.
- 1,083 BTC
- 1,196 addresses
- Drained in just 41 minutes
- Nearly 1 BTC per victim
The third wave tells a different story.
- 208 BTC
- 1,912 addresses
- Average theft: just over 0.1 BTC per victim
Why?
Because the biggest wallets have already been emptied.
Now the attackers are scraping whatever remains.
This Wasn't Magic.
This wasn't quantum computing.
This wasn't breaking Bitcoin's cryptography.
This was a predictable key-generation disaster.
A March 2021 firmware version reportedly generated wallet seeds using a predictable software random number generator instead of relying on the hardware chip's entropy.
That single mistake created a limited pool of reproducible private keys.
Anyone with enough computing power and technical knowledge could regenerate those keys offline—without ever touching the victims' hardware wallets.
Read that again.
Offline.
No phishing.
No malware.
No fake websites.
No device theft.
Just mathematics exploiting weak randomness.
The Attack Is Evolving.
The criminals aren't behaving the same way anymore.
Earlier waves funneled stolen Bitcoin into shared collector wallets, making blockchain tracking relatively straightforward.
Now?
They're changing tactics.
Funds are being routed individually into Pay-to-Witness-Script-Hash (P2WSH) outputs—structures commonly capable of supporting multisignature or timelocked spending.
Stop calling this a "Bitcoin hack." Bitcoin wasn't hacked.
People were.
A catastrophic security failure linked to vulnerable Coldcard-generated wallet seeds has now escalated into one of the largest wallet-draining campaigns in recent memory.
The Numbers Are Brutal
- 1,367 BTC stolen
- Nearly $89 million lost
- 4,585 victim addresses compromised
- Attack still ongoing
According to Galaxy Research, this is now the third wave of coordinated wallet sweeps.
The first wave was devastating.
- 1,083 BTC
- 1,196 addresses
- Drained in just 41 minutes
- Nearly 1 BTC per victim
The third wave tells a different story.
- 208 BTC
- 1,912 addresses
- Average theft: just over 0.1 BTC per victim
Why?
Because the biggest wallets have already been emptied.
Now the attackers are scraping whatever remains.
This Wasn't Magic.
This wasn't quantum computing.
This wasn't breaking Bitcoin's cryptography.
This was a predictable key-generation disaster.
A March 2021 firmware version reportedly generated wallet seeds using a predictable software random number generator instead of relying on the hardware chip's entropy.
That single mistake created a limited pool of reproducible private keys.
Anyone with enough computing power and technical knowledge could regenerate those keys offline—without ever touching the victims' hardware wallets.
Read that again.
Offline.
No phishing.
No malware.
No fake websites.
No device theft.
Just mathematics exploiting weak randomness.
The Attack Is Evolving.
The criminals aren't behaving the same way anymore.
Earlier waves funneled stolen Bitcoin into shared collector wallets, making blockchain tracking relatively straightforward.
Now?
They're changing tactics.
Funds are being routed individually into Pay-to-Witness-Script-Hash (P2WSH) outputs—structures commonly capable of supporting multisignature or timelocked spending.