Home » Bitcoin Cold-Wallet Attack Spreads to 4,500 Addresses as Losses Near $89 Million

Bitcoin Cold-Wallet Attack Spreads to 4,500 Addresses as Losses Near $89 Million

by Melanie Peters


A sophisticated attack exploiting a years-old vulnerability in Bitcoin cold wallets has expanded significantly, with blockchain researchers estimating that nearly $89 million worth of BTC has now been stolen from more than 4,500 wallet addresses. The campaign, which targets wallets created using vulnerable COLDCARD firmware released in March 2021, has evolved through multiple attack waves and may still be ongoing.

According to Onchain Lens, the exploit does not compromise hardware wallets directly. Instead, attackers are reproducing private keys generated from weak recovery seeds, allowing them to drain wallets that have remained offline for years. The incident highlights a rare but severe risk in hardware wallet security: a flaw introduced during wallet creation can permanently undermine even fully air-gapped storage.

Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 millionBitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million

Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million

Three confirmed attack waves

The attack first came to light on July 30, when approximately 1,083 BTC was stolen from 1,196 addresses in just 41 minutes. The speed and coordination of the transactions suggested the attacker had already mapped a large portion of the vulnerable key space before launching automated wallet sweeps.

A second wave followed soon after, while a third wave over the weekend shifted focus toward wallets with much smaller balances. Galaxy Research estimates roughly 207.7 BTC was drained during this latest confirmed phase, bringing total observed losses to approximately 1,367 BTC, worth nearly $89 million, across 4,585 Bitcoin addresses.

Researchers also observed notable changes in the attacker’s behavior.

Instead of consolidating stolen funds into a handful of collector wallets, each victim’s Bitcoin was sent to a separate destination address, making blockchain tracing more difficult. The attacker also switched to Pay-to-Witness-Script-Hash (P2WSH) outputs, which support more advanced spending conditions such as multisignature or timelock scripts.

Meanwhile, each transaction now swept funds from multiple victims simultaneously, improving efficiency compared with the first wave, where addresses were emptied one by one. Galaxy said these operational changes could indicate either the same attacker adapting after public attention or another actor independently exploiting the same vulnerable wallets.

Three confirmed attack wavesThree confirmed attack waves

Three confirmed attack waves

A flaw dating back to 2021

Unlike most crypto thefts involving phishing attacks or malware, this exploit originates from a firmware bug introduced in March 2021.

Researchers found that one COLDCARD firmware release mistakenly generated wallet recovery seeds using a predictable software randomizer rather than the device’s secure hardware random number generator. Because Bitcoin private keys are derived from those recovery seeds, affected wallets were created with significantly weaker cryptographic entropy.

Attackers can therefore reproduce the vulnerable private keys entirely offline using computing power alone, without ever accessing the victim’s hardware wallet or connecting it to the internet.

The implication is particularly alarming for long-term Bitcoin holders. Once a weak recovery seed has been generated, the wallet remains vulnerable regardless of whether the device is disconnected from the internet, locked inside a safe, or stored in a bank vault.

Galaxy estimates the Bitcoin stolen during the first three confirmed waves had remained untouched for an average of 3.18 years, indicating many victims believed their assets were securely stored for the long term.

Researchers warn of a possible fourth wave

The campaign may still be unfolding.

On August 3, Galaxy Research Head Alex Thorn identified transaction patterns consistent with what appears to be a fourth attack wave. During roughly 2.5 hours, researchers detected 218 suspicious transactions involving 462 suspected victim addresses, representing activity roughly 45 times higher than normal.

Galaxy Research Head Alex Thorn’s Status on XGalaxy Research Head Alex Thorn’s Status on X

Galaxy Research Head Alex Thorn’s Status on X

After filtering out false positives and multisignature wallets, Galaxy narrowed the suspected dataset to approximately 709 addresses holding around 448.7 BTC. However, Thorn cautioned that this latest phase has not yet been definitively confirmed because the analysis relies on transaction patterns rather than direct reports from victims.

Despite the uncertainty, Galaxy published the findings immediately because some affected users may still have an opportunity to protect their funds.

A brief chance to recover funds

Unlike earlier attacks, many suspected fourth-wave transactions were broadcast using Replace-by-Fee (RBF), a Bitcoin feature that allows an unconfirmed transaction to be replaced by another paying a higher network fee.

If victims discover the outgoing transaction while it remains in the mempool, they may still be able to submit a higher-fee replacement transaction and transfer their Bitcoin to a secure wallet before miners confirm the attacker’s transfer.

Thorn urged anyone who may have generated a wallet using the vulnerable firmware to immediately verify their balances and migrate remaining funds to wallets created with fresh recovery seeds.

Self-custody faces renewed scrutiny

The incident is also influencing broader Bitcoin custody trends.

Following FTX’s collapse in 2022, many investors embraced the principle of “Not your keys, not your coins,” moving assets from centralized exchanges into self-custodied hardware wallets. The COLDCARD incident shows that while self-custody removes exchange risk, it does not eliminate technical risks arising from flawed wallet generation.

According to CryptoQuant, Bitcoin transfers involving less than 1 BTC briefly surged to around 39,600 BTC in a single day, marking the highest level since FTX’s bankruptcy. Separate blockchain analysis also shows centralized exchanges recorded net inflows exceeding 15,000 BTC on August 1, with platforms including Binance, Kraken, OKX, and River receiving much of the incoming Bitcoin.

Meanwhile, Galaxy Research has shared roughly 600 suspected attacker addresses with U.S. federal investigators, blockchain compliance firms, and cybersecurity partners to support ongoing investigations.

For users who may have initialized wallets using the affected firmware, researchers say updating software alone is insufficient. The safest course of action is to create an entirely new wallet with a fresh recovery seed and immediately transfer all remaining Bitcoin, as any wallet generated using the flawed firmware should be considered permanently compromised.



Source link

You may also like

Leave a Comment