Coldcard Wallet Exploit Drains 1,367 BTC

An illustrative isometric blueprint mapping a crypto security breach, contrasting firmware vulnerability analysis and exploit vectors (left) with asset drainage telemetry and loss tracking (right).

Coldcard wallet exploit continues to drain Bitcoin. Galaxy Research flagged a third wave of sweeps on Sunday.

The attacker emptied wallets worth a few thousand dollars each. Observed losses now total 1,367 BTC. That is nearly $89 million.

Why Coldcard wallet exploit matters

The first wave hit on July 30. It drained 1,083 Bitcoin from 1,196 addresses. The attack took only 41 minutes.

The second wave followed quickly. The third wave struck on Sunday. It drained 208 BTC from 1,912 addresses.

The third wave uses unique destination addresses. Earlier waves used shared collector addresses. The new format uses pay-to-witness-script-hash outputs. This can carry multisignature or timelock conditions.

The third wave batches victims together. Each sweep averages six victims. The first wave took exactly one at a time. The new wave scans only the default path. This is the standard branch a wallet checks first.

The flaw behind the attack

The vulnerability traces to a March 2021 firmware build. The build routed seed generation to a predictable software randomiser. The chip’s hardware randomiser should have been used instead.

This left a bounded set of possible keys. Anyone with the disclosure can reproduce these offline. They never need to touch a device.

The sweeping continues almost three days later. The falling average haul shows the profitable keys are nearly gone.

Related posts

Bitcoin ETF Inflows Hit $172M in July

Circle Trust Charter Secured in New York

Bitcoin Tracks AI Rally as Microsoft Boosts Stocks

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More