Skip to content
Bitcoin

Bitcoin Cold-Wallet Attack Spreads to 4,500 Addresses, Losses Near $89 Million

Glowing Bitcoin coin floating between server racks and connected golden data forms.

The cold-wallet attack exploiting a weak randomness bug in older Coldcard firmware has now spread to over 4,500 Bitcoin addresses, with total losses nearing $89 million, according to Galaxy Research data cited by CoinDesk.

The July 30 opening wave, in which attackers drained 1,083 bitcoin from 1,196 addresses in just 41 minutes, was covered in our earlier report that the attack never touched hardware itself.

Third Wave Sweeps Thousands of Wallets

Galaxy Research flagged a third wave of sweeps early Sunday, roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC. That averages just over a tenth of a bitcoin per victim, indicating the attacker is now emptying wallets worth only a few thousand dollars each.

The onchain patterns have also become more complex, making tracing harder. Observed losses across all three waves now stand at 1,367 bitcoin—nearly $89 million at recent prices—from 4,585 addresses.

Implications and Security Outlook

The vulnerability traces back to a March 2021 Coldcard firmware release that used weak software-based randomness, allowing key reproduction. A separate Coldcard firmware bug had already drained 594 BTC in 25 minutes earlier this year.

In response to the escalating risk, Binance founder CZ urged wallet diversification after the $70M exploit, highlighting the dangers of single-device trust.

The incident underscores the critical importance of verifiable hardware entropy and firmware integrity for cold storage devices. Users are advised to migrate funds from potentially affected addresses and update Coldcard firmware immediately.

BTC-Pulse

Related stories

More coverage from this topic.