Coldcard wallet exploit continues to drain Bitcoin. Galaxy Research flagged a third wave of sweeps on Sunday.
The attacker emptied wallets worth a few thousand dollars each. Observed losses now total 1,367 BTC. That is nearly $89 million.
Why Coldcard wallet exploit matters
The first wave hit on July 30. It drained 1,083 Bitcoin from 1,196 addresses. The attack took only 41 minutes.
The second wave followed quickly. The third wave struck on Sunday. It drained 208 BTC from 1,912 addresses.
The third wave uses unique destination addresses. Earlier waves used shared collector addresses. The new format uses pay-to-witness-script-hash outputs. This can carry multisignature or timelock conditions.
The third wave batches victims together. Each sweep averages six victims. The first wave took exactly one at a time. The new wave scans only the default path. This is the standard branch a wallet checks first.
The flaw behind the attack
The vulnerability traces to a March 2021 firmware build. The build routed seed generation to a predictable software randomiser. The chip’s hardware randomiser should have been used instead.
This left a bounded set of possible keys. Anyone with the disclosure can reproduce these offline. They never need to touch a device.
The sweeping continues almost three days later. The falling average haul shows the profitable keys are nearly gone.