Galaxy Research confirms 1,596 BTC stolen from ~7,300 Coldcard addresses across 3 waves. A suspected 4th wave could push total losses to 2,055 BTC, or ~$130M.
Galaxy Research has confirmed that hackers have stolen 1,596 Bitcoin (BTC), worth more than $100 million, from approximately 7,300 Coldcard hardware wallet addresses across three coordinated attack waves and 14 smaller incidents.
Galaxy also flagged a suspected fourth wave that, if confirmed through victim reports, would push the total to 2,055 BTC, or roughly $130 million. The firm holds the fourth wave with "medium-high" confidence but has kept it out of its confirmed figures as no victims have yet reported being part of it.
What Caused the Vulnerability
The flaw traces to a single code change made on March 1, 2021, in Coldcard firmware developed by Canadian manufacturer Coinkite. That change caused seed generation to fall back to a software-based pseudorandom number generator instead of the device's hardware random number generator.
Seeds generated under the affected firmware were produced with far less entropy than intended, making them searchable offline without physical access to the device.
Block's engineering team, which analyzed the flaw, estimated that the effective search space for Mk3 devices collapsed to roughly 40 bits under some conditions. For Mk4, Mk5, and Coldcard Q devices, the ceiling remained below 73.3 bits, well short of the intended 128-bit security level.
An attacker who can constrain a device's unique identifier, timer state, and prior random number call history can reproduce candidate seeds and check them against public blockchain data.
The affected firmware versions span Coldcard Mk2 and Mk3 devices running versions before 4.2.0, Mk4 and Mk5 devices before 5.6.0, Coldcard Q before version 1.5.0Q, and Edge builds before 6.6.0X on Mk4/Mk5 and 6.6.0QX on the Q model.
Coinkite has released emergency firmware updates for all affected models and said it destroyed remaining inventory manufactured with vulnerable firmware. Updating firmware does not secure an already-generated seed. Users must create a new seed on patched or unaffected hardware and transfer their BTC to addresses controlled by that new seed.
Related Article:Coldcard Firmware Flaw Drains $89M From 4,500 Bitcoin Wallets in 3 Waves
How the Attacks Unfolded
The first sweep occurred on July 30 when an attacker drained 1,082.65 BTC from 1,196 addresses in 41 minutes. Subsequent waves followed at roughly 27-hour intervals, with each sweep showing similar patterns of address aggregation.
Galaxy said it has not confirmed whether the same actor is behind all three waves. The 14 smaller incidents identified alongside the three main waves may represent separate, opportunistic attackers exploiting the now-public vulnerability.
Galaxy Head of Firmwide Research Alex Thorn flagged the possible fourth wave on Aug. 3, noting the transaction pattern in the mempool matched that of previous sweeps. Galaxy said 73 individual victims have contacted the firm directly, and their reports helped researchers identify victim and attacker addresses to share with federal law enforcement, crypto exchanges, and cybersecurity investigators.
