A March 2021 Coldcard firmware bug let attackers steal ~1,367 BTC worth $89M from 4,585 addresses across 3 waves. Galaxy Research warns all vulnerable wallets will be drained.
Crypto Security News
A coding error in a March 2021 Coldcard firmware release has enabled attackers to steal approximately 1,367 Bitcoin (BTC), worth close to $89 million, from 4,585 addresses. Galaxy Research tracked the theft across three separate waves of attacks between July 30 and Aug. 2. The firm flagged the third and most recent wave early on Aug. 2, reporting that roughly 208 BTC was drained from 1,912 addresses between midday July 31 and the morning of Aug. 1 UTC.
The flaw exists in version 4.0.1 of the Coldcard Mk3 firmware. That build mistakenly routed seed phrase generation to a software-based random number generator rather than the dedicated hardware chip inside the device. A software randomizer produces a predictable, bounded range of outputs. Any attacker who knows the flaw can reconstruct the possible private keys offline and check each one against funded addresses, without ever handling a physical wallet.
Three Waves, One Flaw
The third wave also changed its on-chain tactics. Earlier waves funneled victim funds into a small set of shared collector addresses, which made them easy to map. Wave three routed each victim's coins to a unique destination address instead. It also used pay-to-witness-script-hash (P2WSH) outputs, a format that can carry multisignature or timelock conditions, in place of the plain single-key outputs used before.
Additionally, it batched an average of six victims per sweep transaction, where wave one had processed one address at a time. Wave three also limited itself to the default key derivation path rather than scanning multiple branches per seed. Galaxy said it is confident each wave reflects a single internal operator but declined to formally link the three waves to each other. The stolen coins from all three waves have remained in attacker-controlled addresses and have not moved.
Related Article: Crypto Hack Losses Passed $1B in H1 2026, Blockaid Reports
Move Funds Now, Researchers Warn
Thorn posted on X on Aug. 2 that the attack is ongoing. He urged anyone with single-signature funds on Coldcard-generated addresses to move them immediately. He noted the stolen coins had sat dormant for an average of 3.18 years before being swept, indicating the victims were primarily long-term holders. The exploit has reversed a common self-custody practice for many affected users. Large numbers of them are moving BTC off hardware wallets and back onto centralized exchanges or freshly generated addresses.
For some, that response came too late. Canadian fitness coach Jonathan Goodman wrote on X that 18.25 BTC, worth approximately CA$1.6 million ($1.16 million), was swept from his wallets across a seven-minute window on July 29. His private keys had been stored in a physical safety deposit box and had never connected to the internet. "Perhaps the hardest part about this is that I did everything right," Goodman wrote. He added that he is filing reports with police and the Ontario Securities Commission.
