Coldcard Vulnerability: $88M Bitcoin Stolen as Attacks Intensify

Urgent Alert: Coldcard Vulnerability Leads to $88 Million Bitcoin Theft as Attacks Intensify

The critical Coldcard hardware wallet vulnerability continues to send shockwaves through the cryptocurrency community. New insights from research firm Galaxy Research reveal a disturbing escalation in thefts, with confirmed Bitcoin losses now totaling approximately 1,367 BTC, valued at an staggering $88.6 million. The firm issues a stark warning: any assets held in single-signature wallets generated by affected Coldcard devices remain at severe risk of being completely drained, urging immediate action from users.

Galaxy Research’s latest investigation has uncovered a “third wave” of coordinated attacks, during which an additional 207.73 BTC was illicitly transferred. This brings the cumulative confirmed stolen amount to 1,367 BTC, underscoring the relentless nature of the threat. The research team has identified 4,585 affected wallet addresses, emphasizing that these sophisticated attacks are far from over.

The Relentless Pursuit: Attackers Continue to Target Vulnerable Wallets

Contrary to a one-off exploit, Galaxy Research stresses that this is an active and evolving campaign of digital asset theft. The warning is unequivocal: if your Bitcoin is stored in a single-signature wallet created using a vulnerable Coldcard firmware version, it faces an imminent threat of being compromised and transferred by malicious actors. The primary recommendation remains: transfer your assets to a new, secure address without delay.

In a proactive effort to combat this ongoing crisis, Galaxy Research has meticulously compiled a list of approximately 600 suspected on-chain addresses linked to the hackers. This crucial intelligence has been shared with U.S. federal law enforcement agencies, compliance review firms, and cybersecurity experts to aid in the tracking and potential recovery of the stolen funds. The investigation has also benefited significantly from the active participation of numerous victims who have provided transaction records, enabling researchers to analyze intricate on-chain fund flows and attack patterns.

Expert Warning: “This Attack is Not Over”

Alex Thorn, Head of Research at Galaxy Research, took to social media platform X to reiterate the gravity of the situation. He affirmed, “We are still investigating and adding new victim and attacker addresses to the database. This attack is not over. If your assets are still in a Coldcard-generated address, please transfer them immediately.”

This incident has rapidly become one of the most significant Bitcoin self-custody security breaches in recent memory, serving as a stark reminder that even trusted hardware wallets can harbor critical vulnerabilities within their firmware or key generation mechanisms.

Understanding the Coldcard Vulnerability: A Flaw in Randomness

The root of this pervasive issue dates back to a Coldcard firmware update released by Coinkite in March 2021. A critical programming error introduced insufficient randomness during the creation of mnemonic phrases (seed phrases). This flaw allows sophisticated attackers to employ algorithmic methods to infer private keys, thereby gaining unauthorized control over wallet assets.

Alex Thorn further suggests that the highly automated and systematic nature of the hackers’ scanning and stealing operations indicates the potential use of advanced tools, possibly even large language models, to analyze and filter vulnerable wallets. His warning extends to all single-signature Coldcard addresses created after the March 2021 firmware update, stating that their compromise is likely “only a matter of time.”

Interestingly, Galaxy’s analysis reveals that the stolen Bitcoins had remained unmoved for an average of 3.18 years prior to the theft, indicating that a significant portion of the victims are long-term holders. As of now, the funds from these three waves of attacks are still held in hacker-controlled addresses, with no further transfers or sales detected.

Navigating the Aftermath: User Actions and the Future of Self-Custody

The escalating thefts have understandably triggered widespread panic among Coldcard users. Cybersecurity experts are cautioning users to exercise extreme vigilance when transferring assets, emphasizing the importance of not moving funds into new addresses that might themselves be compromised or insecure.

A noticeable trend emerging from this crisis is the accelerated withdrawal of Bitcoin from self-custody wallets. Many affected users are opting to transfer their digital assets to trusted centralized exchanges like Coinbase and Binance, or diligently establishing entirely new, secure wallet addresses to protect their holdings.

This incident serves as a critical lesson in cryptocurrency security, reinforcing the need for continuous vigilance, regular firmware updates, and a thorough understanding of the underlying mechanisms of hardware wallets to safeguard valuable digital assets.


Disclaimer: This article is for market information purposes only. All content and views are for reference only and do not constitute investment advice, nor do they represent the views and positions of Blockcast. Investors should make their own decisions and trades. The author and Blockcast will not bear any responsibility for direct or indirect losses incurred by investors’ transactions.

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these