← All Articles

Coldcard Vulnerability: $89 Million in Bitcoin Drained from 4,500 Wallets: CryptoDailyInk

Key Insight

A critical vulnerability in a March 2021 Coldcard firmware release has led to the systematic draining of nearly $89 million in Bitcoin from over 4,500 addresses. Attackers are exploiting weak key generation, with a third, more sophisticated wave now targeting smaller balances and employing advanced on-chain obfuscation

August 3, 2026, 12:01 AM · 3 min read

Coldcard Flaw Exposes Thousands of Bitcoin Wallets

A significant security vulnerability stemming from a March 2021 firmware release for the popular Coldcard hardware wallet has enabled attackers to systematically drain Bitcoin from thousands of user addresses. The flaw, which routed seed generation to a predictable software randomizer instead of the device's more secure hardware one, created a bounded set of possible keys that could be reproduced offline by sophisticated actors.

Galaxy Research has been tracking the exploit, identifying three distinct waves of attacks that have collectively swept 1,367 Bitcoin, equating to nearly $89 million at current market prices, from a staggering 4,585 addresses. The ongoing nature of these sweeps, almost three days after the initial discovery, underscores the persistent threat and the attacker's continued success in exploiting the compromised key space.

Evolving Attack Tactics and Increased Sophistication

The latest wave of attacks, flagged by Galaxy Research early Sunday, demonstrates a marked increase in sophistication compared to earlier sweeps. While the initial wave on July 30 saw 1,083 BTC drained from 1,196 addresses in just 41 minutes, averaging close to a full Bitcoin per victim, the third wave is targeting significantly smaller balances. Approximately 208 BTC were drained from 1,912 addresses between Friday midday and Saturday morning UTC, averaging just over a tenth of a Bitcoin per victim.

Crucially, the attacker's on-chain behavior has evolved. The first two waves utilized a handful of shared collector addresses, making fund mapping relatively straightforward. However, the third wave sends each victim's coins to its own unique destination, parking them in pay-to-witness-script-hash (P2WSH) outputs. This format, capable of carrying multisignature or timelock conditions, offers greater obfuscation than the plain single-key outputs used previously. Furthermore, the latest sweeps batch an average of six victims into each transaction, a departure from the one-at-a-time approach of the first wave, and focus solely on the default derivation path, rather than testing multiple branches per seed.

Implications for Users and the Broader Ecosystem

While Galaxy Research is confident that each wave is the work of a single operator, the blockchain's inherent anonymity prevents definitive confirmation of whether the same attacker is behind all three. The shift in tactics suggests either the original operator is adapting after being publicly enumerated, or a new actor is independently exploiting the same vulnerable key space.

This incident serves as a stark reminder of the critical importance of cryptographic randomness in securing digital assets. For Coldcard users who generated seeds with the March 2021 firmware, immediate action is paramount. The falling average haul in the latest sweeps suggests that the most profitable end of the vulnerable key space is being depleted, but the threat remains for any un-swept wallets. This event also highlights the ongoing cat-and-mouse game between security researchers and malicious actors, with the latter constantly refining their methods to bypass defenses and exploit vulnerabilities.

Frequently Asked Questions

What is the Coldcard vulnerability?
The vulnerability stems from a specific Coldcard firmware release in March 2021 that used a predictable software randomizer instead of the device's more secure hardware randomizer for generating cryptographic seeds. This allowed attackers to reproduce a bounded set of private keys offline and access funds.

How many wallets and how much Bitcoin have been affected?
As of the latest reports, approximately 1,367 Bitcoin, valued at nearly $89 million, have been drained from 4,585 addresses across three waves of attacks.

What should Coldcard users do if they generated a seed with the March 2021 firmware?
Users who generated their Bitcoin wallet seeds using the Coldcard firmware released in March 2021 should immediately transfer their funds to a new, securely generated wallet. It is crucial to ensure the new wallet's seed is generated using a patched or updated firmware version that utilizes robust hardware randomness.

Market Signal

A March 2021 Coldcard firmware vulnerability, which used a weak software randomizer for key generation, has led to nearly $89 million in Bitcoin being drained from over 4,500 wallets. The attack has occurred in three distinct waves, with the latest wave demonstrating increased sophistication, targeting smaller balances and employing advanced on-chain obfuscation techniques like unique destination addresses and P2WSH outputs. The ongoing nature of the sweeps, even for smaller amounts, indicates that the vulnerable key space is still being actively exploited, posing a continued risk to affected Coldcard users. This incident underscores the critical importance of robust hardware-based randomness in cryptographic key generation and the need for users to stay vigilant about firmware updates and security advisories.

Contributing Author at CryptoDailyInk

Writes on DeFi liquidity, decentralized exchanges, and on-chain capital rotation.