Bitcoin cold-wallet attack hits 4,500 addresses; losses near $89m
A Bitcoin cold-wallet attack tied to Coldcard firmware has spread further, according to Galaxy Research. The March 2021 flaw routed seed generation to weaker software randomness, letting attackers reproduce keys offline and drain funds without touching the devices.
Galaxy Research reports a third wave of sweeps early Sunday: about 208 BTC drained from 1,912 addresses between Friday midday and Saturday morning UTC. Victims typically lost just over 0.1 BTC each. Earlier activity was larger per account—wave one averaged nearly 1 BTC from 1,196 addresses in 41 minutes.
Across all three waves, the Bitcoin cold-wallet attack has taken 1,367 BTC (about $89 million at recent prices) from 4,585 addresses.
The latest wave also changes on-chain behavior. Instead of using the shared “collector” addresses seen in waves one and two, wave three sends each victim’s coins to separate destinations, then parks funds in pay-to-witness-script-hash outputs that can encode multisig or timelock conditions. It also scans only the default derivation path, suggesting either the same operator returning after enumeration or a second actor grinding the same vulnerable key space.
Galaxy Research says it is confident each wave was conducted by one operator but cannot prove whether the same attacker coordinated all three, since blockchain data can’t confirm linkage. It also expects the key space remains partially profitable but increasingly limited, as average take per victim falls.
Neutral
This is a clear negative for wallet security, but it is unlikely to destabilize overall market fundamentals. The Bitcoin cold-wallet attack is driven by a specific firmware randomness flaw, and the victims appear to be clustered around affected key derivation behavior. That can hurt confidence in self-custody practices and may trigger short-term risk-off sentiment, especially among traders focused on security headlines.
However, the attack does not change BTC issuance or core protocol rules, and the reported scope (1,367 BTC total) is small relative to Bitcoin’s broader market liquidity. In past incidents involving wallet or custody exploits, price moves were usually dominated by broader macro/flow factors, while the main impact stayed concentrated in affected users, exchanges, and security-related narratives.
Short term: heightened attention on cold storage hygiene could increase volatility in “security-sensitive” narratives (security tooling, wallet infrastructure), while BTC spot/sentiment may dip modestly.
Long term: the incident reinforces the need for deterministic key management, firmware audits, and faster mitigation/patch rollouts. If updates and forensics reduce future successful sweeps, market impact should fade and shift back to normal technical trading once headlines cool.