Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

요약:Galaxy Research says a third wave of thefts from Coldcard Bitcoin wallets has pushed observed losses to roughly 1,367 BTC across 4,585 addresses.

In brief

  • The Coldcard exploit is ongoing, with Galaxy Research now tracking about $88.6 million stolen across 4,585 addresses in three waves.
  • Galaxy's Alex Thorn described the sweeps as deliberate and likely LLM-orchestrated, warning that every single-sig Coldcard address created after the March 2021 firmware flaw will eventually be drained.
  • The breach has spurred an unusual reversal of the “not your keys, not your coins” ethos as users move Bitcoin back to exchanges.

The theft of Bitcoin from compromised Coldcard hardware wallets is still underway, with researchers now tracking losses of roughly $88 million and warning that every vulnerable device will eventually be emptied.

Galaxy Research said Saturday it has identified a third wave of thefts, in which 207.73 BTC was drained, lifting its observed tally to about 1,367 BTC—around $88.6 million—across 4,585 addresses. The firm called the exploit ongoing and urged anyone holding single-signature funds on a Coldcard to move them at once. Galaxy said it has flagged roughly 600 suspected attacker addresses to federal investigators, compliance firms and cross-industry cyber investigators, crediting victims who shared transaction details for helping map the on-chain patterns.

“I continue to investigate and add new Coldcard victim and attacker addresses to our investigation database,” Galaxys head of research Alex Thorn posted to X. “The attack is ongoing—move your funds off Coldcard-generated addresses immediately if you have not done so.”

i continue to investigate and add new Coldcard victim and attacker addresses to our investigation database tonight

THE ATTACK IS ONGOING -- move your funds off Coldcard-generated addresses immediately if you have not done so. i will provide additional updates on estimated…

The flaw, as Decrypt previously reported, stems from a March 2021 firmware build error on Coinkite's devices that caused seed phrases to be generated with far too little randomness, leaving private keys guessable. Thorn wrote that the sweeps look deliberate and programmatic, probably orchestrated with a large language model, and cautioned that every single-sig Coldcard address created after that 2021 update will eventually be drained, saying it is only a matter of time.

Thorn noted the stolen coins had sat untouched for years before being taken—an average dormancy of 3.18 years—underscoring that the victims were long-term holders. The funds from the three documented waves remain parked in attacker addresses and have not moved.

The fallout has driven a panicked response from affected users, with security experts urging caution when moving funds to new addresses. Many of the affected users are racing to move Bitcoin off self-custody and back onto centralized crypto exchanges, such as Coinbase or Binance, or freshly generated addresses—an inversion of the industry's usual “not your keys, not your coins” ethos.

$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack.

My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.

This part's nerdy, but here's…

For some, the warnings came too late. Canadian coach Jonathan Goodman said in a post on X that 18.25 BTC, worth about $1.6 million Canadian, was swept from his wallets in a seven-minute span on July 29, despite his keys sitting in a safety deposit box that never touched the internet. “Perhaps the hardest part about this is that I did everything right,” he wrote, adding that he is filing reports with police and the Ontario Securities Commission.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

160만 달러 순식간 탈취…콜드카드 지갑 해킹 사례

다음

미국, 28년 규칙 깨고 엔화 구제…비트코인 즉각 반응