EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Coldcard Bitcoin attacks surge, with losses exceeding $90 million

2026-08-03 12:52:07
Bookmark

Alex Thorn, research director at Galaxy Research, reported on August 3 that a fourth wave of suspected attacks against cold wallet Coldcard hardware wallet users had emerged. The latest round of attacks transferred approximately 388.9 BTC through 218 transactions in just a few hours, affecting 462 potential victim addresses.

Root cause of attack: Firmware flaw

These attacks can be traced to a vulnerability in the March 2021 Coldcard firmware release. The vulnerability allows attackers to systematically steal Bitcoin from thousands of wallets by recreating keys generated randomly based on weak software. In a functioning hardware wallet, mnemonic words are created through a dedicated random number generator. Coldcard's firmware was supposed to rely on a dedicated hardware random number generator to generate the random number, but an internal build setting instructed it to skip the generator. So the key generation process turned to a basic software alternative that took the chip serial number and clock register as seeds.

Because each Bitcoin private key originates from the seed, once an attacker can reproduce the seed, he can derive the same wallet and empty the funds without touching the physical device. Coinkite released the patched firmware, but the seeds generated under the vulnerable version are still at risk and cannot be repaired through updates. Security companies have warned that more wallets could face attacks because users cannot reliably determine whether their seeds were generated on vulnerable firmware.

Scale of damage and persistent threat

Prior to the fourth wave of attacks, Galaxy Research had identified three waves of theft involving a total of 4585 addresses and 1367 BTC (approximately US$88.6 million) were stolen. Thorne detailed that in the fourth wave of attacks alone, in approximately two and a half hours, 388.93 BTC items were transferred from 462 victim addresses to 216 newly created addresses through 218 transactions.

Thorne pointed out that some transactions are still in the memory pool, which means affected users may still have a chance to protect their funds. He suggested using the Replace-By-Fee (RBF) feature to add a higher fee, potentially covering pending transactions. Thorne described such money sweeps as deliberate and could be manipulated by artificial intelligence, and warned that all single-signed Coldcard addresses created since the firmware vulnerability emerged in March 2021 will eventually be cleared.

This incident has become one of the largest attacks on Bitcoin's self-hosting, not through malware, phishing or exchange vulnerabilities, but rather through flaws in the encryption key generation process. Security experts said that as cyber threats continue to evolve, the hack highlights growing operational risks in the self-custody space and could accelerate the adoption of regulated custodians and spot Bitcoin ETFs.

Any user who holds BTC at a Coldcard generated address and has not yet transferred funds should immediately use another unaffected wallet to transfer funds based on the newly generated mnemonic.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP