EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coldcard Cold Wallet Bitcoin was stolen and lost US$88.6 million, the third wave of attacks strikes

2026-08-02 12:51:04
Bookmark

Third wave attack cluster pushes estimated losses to US$88.6 million

Weak seed randomness exposes existing wallets to risk

Galaxy Research linked 1,367.05 bitcoins (spread across 4585 addresses) to suspected theft caused by Coldcard seeds.

The third wave attack cluster added 207.7294 bitcoins, making the estimated loss significantly exceed the initially reported US$38 million.

This vulnerability weakens the randomness of seeds, and even with air-gap isolation storage and offline backup, wallets are still at risk.

Firmware updates protect new seeds, but users must migrate funds because the update cannot repair weak seeds that have been generated.

Losses related to the Coldcard seeding vulnerability have climbed to approximately 1,367.05 bitcoins, valued at approximately US$88.6 million. Galaxy Research came up with this number after identifying a third wave of suspected theft clusters.

The current estimate covers 4585 addresses, and the terminal addresses controlled by the attacker still hold 1,366.3865 bitcoins (not yet spent on the chain). Galaxy Research classified this activity as a "suspected hacking attack", so the total is only an on-chain estimate and not a confirmed victim count.


Third wave attack cluster pushes estimated losses to US$88.6 million

The newly identified attack wave involved 207.7294 bitcoins, further expanding the scope of the investigation from the original smaller estimate. Early reports claimed the loss of nearly 594 bitcoins (valued at about $38 million at the time), involving about 500 wallets.

Galaxy Research later recreated a larger fund transfer: In a 41-minute window on July 30, 1,082.65 bitcoins from 1196 addresses were transferred. The transaction spanned six blocks, indicating that the fragile key may have been identified and then transferred funds through a coordinated batch.

Rising totals suggest that preliminary data on cryptocurrency theft often change as analysts connect to new address clusters. Investigators must distinguish between victim wallets, attacker target addresses and intermediary transfers, while avoiding double counting of the same funds.

When funds remain static, the process becomes more difficult because investigators cannot rely on subsequent transfers to clarify ownership patterns. Even so, the unspent balance provides a visible record of the scale of the suspected theft.

This attack required no physical contact, malware, or stealing mnemonic words. Instead, the vulnerability begins when the affected device generates a private seed that controls each wallet.

A software integration in 2021 redirects the seed creation process to MicroPython's deterministic backup generator instead of the expected hardware random number generator. This error significantly reduces the unpredictability needed to protect newly created wallets.

Older Mk2 and Mk3 models produced an effective search space of approximately 40 bits. Newer Mk4, Q and Mk5 models achieve approximately 72 bits instead of the standard 128 bits.


Weak seed randomness exposes existing wallets to risk

Block's engineering and security team traced the vulnerability to the same firmware path. Their review found that device identifiers, timer states, and previous generator calls could all narrow down the range of candidate outputs.

An attacker can then recreate the possible seed stream offline and compare the derived public key to a visible record on the blockchain. This approach exposes wallets to risk even with air-gap isolation storage and offline backup.

Coinkite expanded the scope of affected devices on August 1 and released revised firmware for all affected product lines. However, installing new software does not strengthen seeds created under the randomness of defects.

Affected users must create a new seed on the repaired firmware, verify the backup and receiving addresses, and then send a microtest transaction. The remaining balance cannot be transferred until the test is confirmed to be successful.

Seeds created using at least 50 fair, independent and private dice rolls are not themselves exposed due to this vulnerability. Strong BIP-39 mnemonic adds protection, but migration is still recommended.

TASIGNER, OPENDIME, and SATSCARD were not affected because they used different code bases. A multi-signature setup can reduce similar risks only if enough keys come from independent, uncompromised sources.

This incident shows that hardware isolation protects privacy after it is created, but cannot repair the weak randomness at the beginning. In this case, the weakest link in the wallet appeared before its first transaction.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP