🔗 Also visit:🌐 NewsBuzz⚽ Sports🛠️ SaasTools⚡ Versus💻 TechBuzz🧠 QuizBuzz
📊 MARKETSCheck live crypto prices on CoinMarketCap →
HomecryptoColdcard Wallet Exploit Drains $89M From 4,585 Add...
cryptoanalysis

Coldcard Wallet Exploit Drains $89M From 4,585 Addresses Across Three Attack Waves

Share:𝕏 TwitterRedditWhatsAppTelegram
Advertisement
Coldcard Wallet Exploit Drains $89M From 4,585 Addresses Across Three Attack Waves
⚠️Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments are highly volatile. Always do your own research (DYOR).

A vulnerability in Coldcard hardware wallets' offline key generation system has enabled attackers to steal approximately 1,367 Bitcoin, valued at roughly $89 million, from as many as 4,585 addresses according to newsbytesapp.com. The exploit targeted devices that are not directly connected to the internet, challenging assumptions about the security of air-gapped cold storage. Galaxy Research mapping shows the attack occurred in multiple waves, with a third wave reported early Sunday, and investigators indicate the stolen funds remain entirely unspent as of the latest on-chain analysis from ambcrypto.com.

How the Coldcard firmware vulnerability worked

The breach exploited an internal build setting in Coldcard's firmware that instructed the device to skip its hardware random number generator (RNG) and instead use a basic software substitute for seed generation. According to newsbytesapp.com, this software substitute was seeded with the chip's serial number and clock registers, making it possible for an attacker to narrow down or reproduce these values using their own hardware. When a wallet is created, the device generates an unpredictable number called the seed, which forms the basis for every address and private key derived from it using fixed public rules. By reducing the entropy source to predictable hardware identifiers, the vulnerability made the range of possible keys countable instead of astronomically large, allowing attackers to generate candidate seeds, derive the addresses each seed would produce, and check those against the public blockchain.

Which Coldcard models are affected

Investigators found that key generation could be predicted on older MK2 and MK3 models of Coldcard wallets. While Coldcard's maker has warned that only MK3 owners are affected, an investigation suggests that MK2, MK4 Q, and MK5 models may also be at risk, according to newsbytesapp.com. This discrepancy between the manufacturer's advisory and independent findings raises questions about the full scope of devices compromised by the firmware flaw. The attack targeted the offline key generation process itself, meaning wallets created on vulnerable firmware versions could be at risk regardless of whether the device was ever connected to a network.

Attack timeline and scale across three waves

Galaxy Research's mapping shows the attack was conducted in multiple waves, with the third wave of thefts reported early Sunday. The latest discovery links the incident to 4,585 addresses drained across three waves, totaling 1,367.05 BTC worth about $88.6 million, as reported by ambcrypto.com. The latest wave alone drained 207.73 BTC from 1,912 addresses, extending earlier estimates of 2,673 wallets and 1,158.81 BTC. msn.com reports that a Coldcard firmware bug may have let attackers steal roughly $70 million in bitcoin in under an hour, and the company says attacks are still ongoing. The expanding scope suggests investigators continue to uncover additional linked addresses as on-chain analysis progresses.

Attacker behavior: consolidation over liquidation

On-chain analysis reveals the stolen Bitcoin remains 100% unspent, indicating the attacker prefers consolidation over immediate liquidation. According to ambcrypto.com, the exploit cluster received 1,159.42 BTC, worth about $72.71 million, from 870 compromised addresses before consolidating the funds into eight verified wallets. The attacker has moved only 0.06 BTC to a fresh address, leaving roughly 1,159.35 BTC untouched. This pattern suggests operational planning rather than opportunistic selling, with the attacker prioritizing control, organization, and reducing exposure before attempting larger transfers. The funds' visibility on-chain allows investigators to monitor future movements, though coordinated outbound transfers would mark a transition from a contained incident into a far more complex tracing challenge.

Role of blockchain data providers in the attack

The attacker used a popular blockchain data provider to query the source addresses during the theft. According to newsbytesapp.com, the provider's internal logs matched with what investigators described as "extraordinary specificity," suggesting they had been providing routine blockchain services to requests that gave no indication of their malicious purpose. This detail highlights how legitimate infrastructure can be leveraged in attacks without the service provider's awareness, as the queries appeared to be standard blockchain lookups rather than overtly suspicious activity.

What happens next for affected users and investigators

The investigation enters a more decisive phase as future on-chain movements will reveal whether the operation shifts from fund management to fund extraction. Transfers to regulated exchanges could expose identities through KYC procedures, creating opportunities for intervention, while movements through mixers or cross-chain bridges would fragment the transaction trail and complicate blockchain analysis, according to ambcrypto.com. Transaction frequency, address clustering, and routing patterns will become more important than balance size alone. Continued inactivity would preserve clear investigative leads and strengthen monitoring efforts. For Coldcard users, the discrepancy between the manufacturer's advisory (MK3 only) and independent findings (potentially MK2, MK4 Q, and MK5) means owners of multiple model generations should verify their firmware versions and consider migrating funds to devices with verified entropy sources until a comprehensive security audit is completed.

Advertisement
Tags:#crypto security#hardware wallets#Bitcoin#cold storage#cybersecurity
Share:𝕏 TwitterRedditWhatsAppTelegram
📰
CryptoNews Editorial Team
Editorial Team

CryptoNews is an independent digital publication covering cryptocurrency, blockchain, and digital finance. Our editorial team uses AI-assisted research and drafting tools with human editorial review. Every article is checked against cited sources before publishing. See our Editorial Guidelines for how we work.

📚 Related Articles

💰
Solana ETFs Log Inflows Every July Day as Morgan Stanley Joins Race
5 min read
💰
Crypto's Record Half-Year: 212 Exploits Drain $1.1 Billion in H1 2026
5 min read
💰
Tokenized RWAs Reach $33.5 Billion as DTCC Starts On-Chain Treasuries
5 min read
💰
GENIUS Act Rules Hit July 18 Deadline as Banks Chase $263B Stablecoins
5 min read
Advertisement