Back to top
  • 공유 Share
  • 인쇄 Print
  • 글자크기 Font size
URL copied.

Coldcard Wallet Exploit Expands as Bitcoin Theft Reaches $89 Million

Coldcard Wallet Exploit Expands as Bitcoin Theft Reaches $89 Million. Source: Image by PIRO from Pixabay

A third wave of attacks targeting vulnerable Coldcard-generated Bitcoin wallets has drained another 208 BTC from 1,912 addresses, pushing total losses to 1,367 BTC—worth nearly $89 million—according to Galaxy Research. The latest wave occurred between Friday midday and Saturday morning UTC, signaling that the attacker continues exploiting wallets created with compromised keys.

Unlike the initial attacks, which averaged nearly one Bitcoin stolen per victim, the third wave took just over 0.1 BTC from each affected address, suggesting the highest-value wallets have already been emptied. The first wave, launched on July 30, stole 1,083 BTC from 1,196 addresses in only 41 minutes.

Galaxy Research noted that the latest campaign uses a different on-chain strategy. Instead of sending stolen funds to a small group of collection wallets, each victim’s Bitcoin is transferred to a unique destination address. The stolen funds are also being stored in pay-to-witness-script-hash (P2WSH) outputs, a format that supports advanced features such as multisignature wallets and timelocks, replacing the simpler single-key outputs used in earlier attacks.

The third wave also grouped an average of six victims into each transaction, compared with one victim per transaction during the first wave. Additionally, the attacker scanned only the default derivation path—the primary branch wallets check first—rather than testing multiple key branches.

Researchers believe each wave was likely carried out by a single operator, but they cannot determine whether the same individual is responsible for all three campaigns or if multiple attackers are independently exploiting the same vulnerability.

The security issue stems from a March 2021 Coldcard firmware release that mistakenly relied on a predictable software random number generator instead of the device’s hardware-based randomizer during seed generation. This created a limited pool of possible private keys that attackers can reproduce offline with sufficient computing power, without requiring physical access to the hardware wallet.

With wallet sweeps continuing nearly three days after the first attack, researchers warn that vulnerable Coldcard users remain at risk, even as the average amount stolen per wallet continues to decline.

<Copyright ⓒ TokenPost, unauthorized reproduction and redistribution prohibited>

Most Popular

Comment 0

Comment tips

Great article. Requesting a follow-up. Excellent analysis.

0/1000

Comment tips

Great article. Requesting a follow-up. Excellent analysis.
1