Coldcard drainers cash out 3 years of patience, $88M later 😅
Back to feed

Coldcard drainers cash out 3 years of patience, $88M later 😅

Theft of Bitcoin from compromised Coldcard hardware wallets has climbed to roughly $88.6 million, with researchers warning the attack is still in progress and every vulnerable single-signature device is expected to be emptied. Galaxy Research said Saturday it has identified a third wave of thefts in which 207.73 BTC was drained, lifting its observed tally to about 1,367 BTC across 4,585 addresses. The firm urged anyone holding single-signature funds on a Coldcard to move them at once. Galaxy added that it has flagged roughly 600 suspected attacker addresses to federal investigators, compliance firms and cross-industry cyber investigators, crediting victims who shared transaction details for helping map the on-chain patterns.

The flaw stems from a March 2021 firmware build error on Coinkite's devices that caused seed phrases to be generated with far too little randomness, leaving private keys guessable. Galaxy Research's head of research Alex Thorn wrote on X that the sweeps look deliberate and programmatic, probably orchestrated with a large language model, and cautioned that every single-sig Coldcard address created after that 2021 update will eventually be drained, saying it is only a matter of time. Thorn noted the stolen coins had sat untouched for years before being taken — an average dormancy of 3.18 years — underscoring that the victims were long-term holders.

Earlier tracing by Galaxy Research identified 1,196 addresses linked to the incident that lost 1,082.65 Bitcoin, worth about $70.2 million at the time of the transactions. Galaxy said the Bitcoin movements occurred between 1:10 AM and 1:51 AM UTC on July 30 across blocks 960,183 to 960,191, about 30 hours before Coldcard published its first security advisory, according to a Friday X post. The identified transactions shared a pattern, including identical 30 satoshis per virtual byte fees and no change outputs. Galaxy said the initial attack activity is identifiable on-chain through this pattern but noted that future attacks against Coldcard-generated addresses may not follow the same fingerprint.

Coinkite co-founder Rodolfo Novak said in an X post on Friday that the company takes responsibility for the firmware bug and is working to determine the full scope of the issue. Novak said Coinkite released a hotfix to remove the software fallback path but warned that the update does not protect seeds generated on vulnerable firmware, advising users who generated seeds on vulnerable firmware to move their funds to a new seed. Earlier preliminary analysis by AnchorWatch CEO and co-founder Rob Hamilton estimated that 594.48 Bitcoin, worth around $38 million, moved across 500 transactions within a three-block window. The funds from the three documented waves remain parked in attacker addresses and have not moved.

For some users, the warnings came too late. Canadian coach Jonathan Goodman said in a post on X that 18.25 BTC, worth about $1.6 million Canadian, was swept from his device on July 29 in the Coldcard hack.

Mentioned Coins

$BTC
Share:
Publishercryptonewsroom.xyz
Published—
CategorySecurity

Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.

See our Terms of Service, Privacy Policy, and Editorial Policy.