A Bitcoin cold-wallet attack tied to weak Coldcard-generated keys has now spread across 4,585 addresses, with observed losses nearing $89 million, according to CoinDesk’s report on Galaxy Research findings. The latest wave shows the attacker moving from larger balances toward smaller wallets worth only a few thousand dollars each.
The attack is important because it targets the idea many Bitcoin holders rely on most: that cold storage is safer because private keys are generated and kept offline. In this case, the weakness is not ordinary online theft. Researchers say vulnerable seeds were generated with predictable software randomness, making it possible for an attacker to reproduce keys offline and sweep funds without touching the physical device.
What changed in the latest attack wave
CoinDesk reports that Galaxy Research flagged a third wave of sweeps early Sunday. That wave drained about 208 bitcoin from 1,912 addresses between Friday midday and Saturday morning UTC. The average victim balance was just over one-tenth of a bitcoin, smaller than the first wave, which reportedly took 1,083 bitcoin from 1,196 addresses in 41 minutes.
The numbers suggest the most valuable exposed wallets may already have been drained. That does not make the risk over. It means the attacker, or another operator searching the same weak key space, may now be working through smaller balances that were still worth taking.
The latest wave also changed transaction behavior. Earlier sweeps were easier to map because funds moved into a small number of shared collector addresses. The third wave sent coins from each victim to separate destinations and used pay-to-witness-script-hash outputs, a format that can support multisignature or timelock conditions. That makes the flow harder for public observers to follow.
Why Coldcard-generated keys became vulnerable
The Bitcoin cold-wallet attack traces back to a Coldcard firmware issue from March 2021, according to the report. That firmware path routed seed generation to a predictable software randomizer instead of the hardware random-number source. If a seed was created under vulnerable conditions, the possible key space may be small enough for attackers with enough compute to reproduce.
This distinction matters for users. Updating firmware can prevent new weak seeds from being created, but it cannot make an old weak seed stronger. If a wallet was created with a predictable seed, the recovery words remain the same secret even after a firmware update. Moving that same seed into a different device does not solve the underlying issue.
The safer path for potentially affected users is to create a completely new wallet seed on fixed firmware or a trusted alternative setup, verify the backup, send a small test transaction, and then move the remaining funds. The process should be calm and deliberate because rushed migrations can introduce their own mistakes.
Why the blockchain cannot answer everything
Galaxy Research reportedly believes each wave is internally consistent with one operator, but the public blockchain cannot prove whether all three waves were run by the same attacker. That is a useful reminder about on-chain analysis. It can show timing, outputs, wallet patterns, and movement, but it cannot always identify who controls the keys behind those movements.
That ambiguity also creates a race. Once a vulnerability is public, more than one actor may try to scan the same exposed key space. Even if the original attacker stops, others can attempt the same offline reconstruction. For users with exposed funds, waiting for attribution does not reduce the risk.
The switch to smaller balances shows the economics of the attack are changing. The biggest wallets may have been hit first because they offered the highest reward. As the remaining exposed wallets become smaller, the attacker must decide whether the cost of scanning and sweeping is still worth it. At current bitcoin prices, even small balances can justify automation.
What Bitcoin holders should take from this
The lesson is not that hardware wallets are useless. Good hardware wallets remain one of the strongest protections against malware, exchange failure, and remote account compromise. The lesson is that seed generation is the foundation of self-custody. If that foundation is weak, the rest of the security stack cannot fully compensate.
Anyone who created a Coldcard wallet during the affected period should check the manufacturer’s current guidance and avoid assuming that a firmware update alone is enough. Users who added strong independent dice-roll entropy or a strong passphrase may have a different risk profile, but uncertainty should be treated seriously when real funds are at stake.
The Bitcoin cold-wallet attack is now one of the clearest examples of how a small randomness failure can become a large on-chain loss years later. In Bitcoin custody, private keys do not forgive old mistakes. Once a weak seed is known to be possible, moving funds to a newly generated, properly backed-up wallet is the only durable fix.
Source: CoinDesk
