Coldcard Bitcoin Drain Reaches $88M as Attack Ongoing
Galaxy Research reports $88.6M in Bitcoin stolen from Coldcard wallets due to firmware flaw, affecting 4,585 addresses. Attack ongoing, users urged to move funds; many rush back to exchanges, reversing 'not your keys, not your coins.'
Quick Take
$88.6M BTC stolen across 4,585 Coldcard wallets in three waves.
Flaw from March 2021 firmware caused weak seed phrases, enabling brute-force attacks.
Attack ongoing; Galaxy warns all vulnerable wallets eventually will be drained.
Users panic, moving funds back to exchanges despite self-custody ethos.
Market Impact Analysis
BearishOngoing theft and panic selling to exchanges could cause short-term sell pressure and damage confidence in self-custody.
Speculation Analysis
Key Takeaways
- $88.6M in Bitcoin stolen from 4,585 Coldcard wallets as exploit continues into third wave.
- Flawed March 2021 firmware created weak seed phrases, enabling brute-force key guessing.
- Galaxy warns every vulnerable single-signature Coldcard address will eventually be drained.
- Panicked users rush funds back to exchanges, reversing the 'not your keys, not your coins' ethos.
What Happened
An ongoing exploit targeting Coldcard hardware wallets has drained over $88 million in Bitcoin, Galaxy Research revealed. The attack, now in its third wave, has siphoned 1,367 BTC from 4,585 addresses. The root cause: a firmware flaw from March 2021 that generated seed phrases with insufficient entropy, making private keys guessable. Despite the flaw existing for years, the funds only began moving recently. Long-term holders—coins sat an average of 3.18 years—are the primary victims. Galaxy's head of research Alex Thorn warned the attack is ongoing and urged immediate fund relocation.
The Numbers
So far, $88.6 million has been stolen across three distinct sweeps. The third wave alone accounted for 207.73 BTC. Attacker addresses have not moved the stolen funds, indicating a deliberate accumulation strategy. Galaxy has flagged roughly 600 suspected attacker addresses to authorities. The average dormancy of victim coins was over three years, suggesting patient long-term holders were targeted. Every single-signature Coldcard address created after the flawed update is at risk, according to Thorn.
Why It Happened
The breach traces back to a March 2021 firmware build error by manufacturer Coinkite. The error caused seed phrases to be generated with far too little randomness. This made private keys vulnerable to brute-force attacks. Experts believe the sweeps are programmatic and possibly orchestrated using large language models. The delay between the flaw and the thefts suggests attackers may have recently developed the tooling to efficiently crack the weak keys. Once keys are compromised, draining wallets is straightforward.
Broader Impact
The attack is shaking crypto's self-custody foundation. Panicked users are moving Bitcoin back to centralized exchanges—a stark reversal of the 'not your keys, not your coins' mantra. This could cause short-term sell pressure as holders seek safety. The incident also raises questions about hardware wallet security audits and long-term firmware support. Trust in Coldcard and similar devices may erode, potentially slowing adoption of self-custody solutions.
What to Watch Next
- Any further sweeps as attackers continue exploiting vulnerable wallets; Galaxy is monitoring on-chain patterns.
- User migration trends and exchange inflow spikes, which could indicate panic selling.
- Coinkite's official response, potential patches, or legal actions; firm so far has not issued detailed guidance.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.