Coldcard Vulnerability Triggers $89M Bitcoin Heist, Hits Thousands of Wallets

security
📉 Bearish
⏱ 3 min read
$BTC

In a sweeping attack exploiting a Coldcard firmware vulnerability, nearly $89 million in Bitcoin has been drained from 4,585 wallet addresses across three attack waves, exposing evolving risks in hardware wallet security.

What Happened

Galaxy Research has identified a series of attacks exploiting a weakness in Coldcard wallets, resulting in the theft of 1,367 BTC from 4,585 addresses by leveraging flawed key generation processes. These attacks occurred in three distinct waves, each displaying a progression in both tactics and target selection. While the initial wave in July 2023 targeted higher-balance wallets—averaging nearly one full Bitcoin per victim—the latest wave switched focus, draining smaller balances but employing more sophisticated onchain behaviors that make transactions harder to trace. Notably, this third wave batched multiple victims in each sweep and altered the method of collecting stolen funds, parking them in pay-to-witness-script-hash outputs instead of the easily mapped single-key addresses used previously.

The vulnerability at the core of these exploits traces back to a firmware build released in March 2021, which inadvertently routed cold-wallet seed generation to a software randomizer rather than reliable hardware-based entropy. This flaw produced a bounded, predictable set of private keys, enabling attackers with disclosure and adequate computing resources to offline-replicate vulnerable wallets and execute mass sweeps across the Bitcoin blockchain. Despite strong evidence that each attack wave is managed internally by a single operator, Galaxy Research declined to confirm any connection or coordination across all three, citing inherent transparency gaps in public blockchain data.

Why It Matters

The scale and evolution of these attacks highlight the ongoing risk that low-quality entropy sources and unreviewed firmware introduce to crypto asset custody—even among users relying on widely trusted hardware wallets. The recent targeting of smaller balances and adoption of harder-to-map onchain tactics signals that attackers are rapidly adapting to community responses and public blockchain surveillance. In the wider context, such incidents illustrate a growing need for higher standards in firmware review, vulnerability disclosure, and operational security procedures for self-custody solutions. This breakdown in the key management supply chain can quickly propagate systemic threats, particularly as crypto adoption pushes more mainstream users toward hardware-based storage.

Beyond the immediate losses, the escalating complexity of each attack wave raises red flags about the robustness of current wallet security paradigms. Historically, cold storage has been treated as a near-inviolable best practice; this incident calls that assumption into question, reminding the market of persistent software and hardware risks. The evolving tactics—ranging from changes in transaction output structure to strategic batching—reflect how adversaries continue to find and exploit any cracks in wallet implementations, entrenching the importance of ongoing threat modeling and supply chain audits across the sector.

Key Takeaways

  • A Coldcard firmware vulnerability led to the theft of nearly $89M in BTC from thousands of wallets.
  • The attack evolved to use advanced transaction patterns, making tracing more difficult.
  • Underlying flaw was a predictable software randomizer used for key generation in 2021 firmware.
  • Security reviews and robust entropy sources are essential in hardware wallet design.

What’s Next

The market is likely to watch Coldcard’s response—both in terms of patching the exposed vulnerability and communicating with affected users. Ongoing onchain monitoring may uncover further sweeps, especially if other wallets or manufacturers share similar flaws. For hardware wallet users, this event reinforces the importance of keeping firmware updated, implementing multisignature protection, and scrutinizing derivation paths. Industry-wide, the breach may trigger renewed calls for standardized hardware wallet security audits and open-source firmware review processes, while institutional stakeholders will be reassessing operational security protocols in the wake of such a substantial loss. The broader question remains how wallet manufacturers can consistently close entropy and supply chain gaps as attack sophistication grows.

🧠 HafidWatch Take

A vulnerability in Coldcard wallet firmware has enabled a large-scale attack, draining nearly $89 million in BTC from 4,585 addresses across three distinct waves. The most recent phase deployed more complex, harder-to-track onchain strategies and targeted smaller balances, exposing evolving risks in wallet key security.

🔗 Tools mentioned in this article

Affiliate disclosure: Links above may earn HafidWatch a commission at no cost to you.

Daily crypto intelligence. Before the market opens.

Including the Divergence Index — the sentiment gap no other newsletter tracks. Free, every morning at 7:30am ET.

✓ Free forever  ·  ✓ No spam  ·  ✓ 50+ sources monitored

Want it faster? Join the community:

Type above and press Enter to search. Press Esc to cancel.