Coldcard Wallet Exploit Spreads, $89M in BTC at Risk
A third wave of attacks exploiting weak Coldcard-generated keys has expanded to 4,500 Bitcoin addresses, with losses approaching $89 million. The attacker now targets smaller balances and alters on-chain collection methods, signaling an evolving threat, underscoring the importance of robust key generation.
Quick Take
Third wave of sweeps targets Bitcoin cold wallets via weak Coldcard keys.
Losses near $89 million across 4,500 compromised addresses.
Attacker now focusing on smaller balances and new collection techniques.
Galaxy Research flags evolving onchain behavior.
Market Impact Analysis
BearishThe cold-wallet attack on Bitcoin may trigger short-term bearish sentiment due to security concerns and potential loss of confidence in storage solutions.
Speculation Analysis
Key Takeaways
- A third wave of Coldcard wallet attacks has swept 4,500 Bitcoin addresses, pushing total losses near $89 million.
- The attacker is now honing in on smaller balances, signaling a refined, more systematic approach to draining funds.
- Galaxy Research identified changing on-chain collection methods, indicating the exploit is evolving and harder to trace.
- The root cause remains weak key generation by Coldcard devices, highlighting persistent hardware wallet vulnerabilities.
What Happened
A sophisticated exploit targeting Bitcoin cold wallets has now compromised 4,500 addresses, nearing $89 million in total losses. Galaxy Research detected the third wave of sweeps on Thursday, linked to weak keys generated by Coldcard hardware wallets. The attacker, initially focused on high-value targets, has pivoted toward smaller balances, altering on-chain fund movement patterns to evade detection. This marks an escalation in both scale and sophistication of the multi-year campaign. The weaknesses stem from improper entropy during key creation, making private keys predictable. Users who generated seeds on affected Coldcard devices remain at risk, even if they moved funds later. The evolving tactics suggest the attacker is systematically draining any accessible wallet, no matter how small.
The Numbers
The attack now spans 4,500 distinct Bitcoin addresses, up from a few hundred in earlier waves. Losses have ballooned to nearly $89 million, with the attacker sweeping funds to new wallets using obfuscation techniques. Median stolen amounts per address have dropped as the attacker shifts to smaller, less-monitored targets. Galaxy Research noted the third wave shows a 40% increase in the number of transactions compared to previous sweeps, reflecting the broader net. The total value at risk remains difficult to estimate, as dormant wallets with weak keys could still be drained.
Why It Happened
The vulnerability originated from Coldcard's key generation process, which produced insufficient randomness under certain conditions. This allowed the attacker to derive private keys for wallets that appeared secure. The exploit wasn't a single event but a recurring weakness that went undetected for years, underscoring the critical importance of verifiable entropy in hardware wallets. Coldcard's delayed firmware fixes left a large window for exploitation. The attacker's ability to sustain operations over multiple waves suggests automated scanning for vulnerable keys. Once a key is computed, funds can be swept instantly, making timeliness of defense critical.
Broader Impact
This incident raises fresh concerns about hardware wallet security across the industry. It may accelerate calls for open-source verification and third-party audits of wallet firmware. Exchanges and custodians could face pressure to blacklist tainted addresses, while regulators may scrutinize wallet providers more closely. For Bitcoin, the repeated breaches highlight the ongoing tension between self-custody ideals and practical safety. Users may reconsider hardware wallets in favor of multi-signature or custodian solutions, shifting the market landscape.
What to Watch Next
- Whether Coldcard issues a recall or mandatory firmware update for affected devices, and how quickly users respond.
- If the attacker expands to other blockchains or wallets with similar key generation flaws, potentially widening the crisis.
- Any movement from law enforcement to trace and freeze stolen funds, given the size and persistence of the theft.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.