A complicated assault exploiting a years-old vulnerability in Bitcoin chilly wallets has expanded considerably, with blockchain researchers estimating that almost $89 million value of BTC has now been stolen from greater than 4,500 pockets addresses. The marketing campaign, which targets wallets created utilizing weak COLDCARD firmware launched in March 2021, has advanced by means of a number of assault waves and should still be ongoing.
In line with Onchain Lens, the exploit doesn’t compromise {hardware} wallets instantly. As an alternative, attackers are reproducing personal keys generated from weak restoration seeds, permitting them to empty wallets which have remained offline for years. The incident highlights a uncommon however extreme threat in {hardware} pockets safety: a flaw launched throughout pockets creation can completely undermine even totally air-gapped storage.

Bitcoin cold-wallet assault spreads to 4,500 addresses as losses close to $89 million
Three confirmed assault waves
The assault first got here to mild on July 30, when roughly 1,083 BTC was stolen from 1,196 addresses in simply 41 minutes. The velocity and coordination of the transactions instructed the attacker had already mapped a big portion of the weak key house earlier than launching automated pockets sweeps.
A second wave adopted quickly after, whereas a 3rd wave over the weekend shifted focus towards wallets with a lot smaller balances. Galaxy Analysis estimates roughly 207.7 BTC was drained throughout this newest confirmed section, bringing whole noticed losses to roughly 1,367 BTC, value practically $89 million, throughout 4,585 Bitcoin addresses.
Researchers additionally noticed notable adjustments within the attacker’s habits.
As an alternative of consolidating stolen funds right into a handful of collector wallets, every sufferer’s Bitcoin was despatched to a separate vacation spot tackle, making blockchain tracing tougher. The attacker additionally switched to Pay-to-Witness-Script-Hash (P2WSH) outputs, which help extra superior spending situations reminiscent of multisignature or timelock scripts.
In the meantime, every transaction now swept funds from a number of victims concurrently, bettering effectivity in contrast with the primary wave, the place addresses had been emptied one after the other. Galaxy stated these operational adjustments might point out both the identical attacker adapting after public consideration or one other actor independently exploiting the identical weak wallets.


Three confirmed assault waves
A flaw courting again to 2021
Not like most crypto thefts involving phishing assaults or malware, this exploit originates from a firmware bug launched in March 2021.
Researchers discovered that one COLDCARD firmware launch mistakenly generated pockets restoration seeds utilizing a predictable software program randomizer slightly than the gadget’s safe {hardware} random quantity generator. As a result of Bitcoin personal keys are derived from these restoration seeds, affected wallets had been created with considerably weaker cryptographic entropy.
Attackers can due to this fact reproduce the weak personal keys completely offline utilizing computing energy alone, with out ever accessing the sufferer’s {hardware} pockets or connecting it to the web.
The implication is especially alarming for long-term Bitcoin holders. As soon as a weak restoration seed has been generated, the pockets stays weak no matter whether or not the gadget is disconnected from the web, locked inside a protected, or saved in a financial institution vault.
Galaxy estimates the Bitcoin stolen in the course of the first three confirmed waves had remained untouched for a mean of 3.18 years, indicating many victims believed their property had been securely saved for the long run.
Researchers warn of a doable fourth wave
The marketing campaign should still be unfolding.
On August 3, Galaxy Analysis Head Alex Thorn recognized transaction patterns per what seems to be a fourth assault wave. Throughout roughly 2.5 hours, researchers detected 218 suspicious transactions involving 462 suspected sufferer addresses, representing exercise roughly 45 occasions greater than regular.


Galaxy Analysis Head Alex Thorn’s Standing on X
After filtering out false positives and multisignature wallets, Galaxy narrowed the suspected dataset to roughly 709 addresses holding round 448.7 BTC. Nonetheless, Thorn cautioned that this newest section has not but been definitively confirmed as a result of the evaluation depends on transaction patterns slightly than direct stories from victims.
Regardless of the uncertainty, Galaxy printed the findings instantly as a result of some affected customers should still have a chance to guard their funds.
A short probability to get better funds
Not like earlier assaults, many suspected fourth-wave transactions had been broadcast utilizing Exchange-by-Price (RBF), a Bitcoin characteristic that permits an unconfirmed transaction to get replaced by one other paying the next community price.
If victims uncover the outgoing transaction whereas it stays within the mempool, they might nonetheless be capable to submit a higher-fee alternative transaction and switch their Bitcoin to a safe pockets earlier than miners affirm the attacker’s switch.
Thorn urged anybody who might have generated a pockets utilizing the weak firmware to right away confirm their balances and migrate remaining funds to wallets created with recent restoration seeds.
Self-custody faces renewed scrutiny
The incident can be influencing broader Bitcoin custody traits.
Following FTX’s collapse in 2022, many buyers embraced the precept of “Not your keys, not your cash,” transferring property from centralized exchanges into self-custodied {hardware} wallets. The COLDCARD incident exhibits that whereas self-custody removes change threat, it doesn’t remove technical dangers arising from flawed pockets technology.
In line with CryptoQuant, Bitcoin transfers involving lower than 1 BTC briefly surged to round 39,600 BTC in a single day, marking the best stage since FTX’s chapter. Separate blockchain evaluation additionally exhibits centralized exchanges recorded web inflows exceeding 15,000 BTC on August 1, with platforms together with Binance, Kraken, OKX, and River receiving a lot of the incoming Bitcoin.
In the meantime, Galaxy Analysis has shared roughly 600 suspected attacker addresses with U.S. federal investigators, blockchain compliance corporations, and cybersecurity companions to help ongoing investigations.
For customers who might have initialized wallets utilizing the affected firmware, researchers say updating software program alone is inadequate. The most secure plan of action is to create a completely new pockets with a recent restoration seed and instantly switch all remaining Bitcoin, as any pockets generated utilizing the flawed firmware needs to be thought-about completely compromised.

