
A years-old vulnerability tied to a Coldcard firmware release continues to haunt bitcoin holders. Galaxy Research has identified a third wave of opportunistic sweeps that are draining funds from wallets whose keys were generated using weak software-based randomness. The attack has now expanded to roughly 4,585 addresses, and the cumulative haul is approaching $89 million.
The attacks exploit a flaw in a March 2021 Coldcard firmware release. That version of the firmware used a random number generator that failed to produce sufficient entropy in certain conditions. Because the security of a bitcoin wallet depends entirely on the unpredictability of its private key, any weakness in the key-generation process can be catastrophic. An attacker who can reproduce the conditions under which a key was created can derive the private key and move the funds without any interaction with the device owner.
Three Waves of Sweeps
Galaxy Research's latest analysis shows that the attacker has executed three distinct waves of sweeps. In total, 1,367 bitcoin have been moved from 4,585 addresses. At recent prices, that represents nearly $89 million in losses. The first two waves were notable for their scale and speed, but the third wave reveals a change in tactics.
In the latest wave, the attacker is deliberately targeting smaller balances. This shift suggests that larger and more obvious targets have been exhausted, or that the attacker is trying to avoid drawing attention. By sweeping addresses with smaller holdings, the attacker may also reduce the likelihood of triggering alarms or exchange-level risk controls.
Changing On-Chain Behavior
Beyond the size of the balances, the on-chain behavior has evolved. Earlier sweeps were relatively straightforward: the attacker would move funds from a compromised address to a new wallet, often in a single transaction. The third wave uses more complex patterns. Funds are being routed through multiple intermediate addresses, split into smaller pieces, and sometimes delayed before being consolidated.
This behavior makes it more difficult for blockchain analysts and exchange compliance teams to trace the destination of stolen funds. It also complicates efforts to blacklist addresses or freeze assets. The attacker appears to be learning from previous responses and adapting their methods.
Root Cause: Weak Randomness in Coldcard Firmware
The root cause of the vulnerability lies in the way some Coldcard devices generated private keys. In the March 2021 firmware release, the device's software random number generator did not always combine hardware entropy sources correctly. In certain edge cases, the generated seed could be replicated if an attacker knew the exact state of the device at the time of creation.
Coldcard is generally regarded as one of the most secure hardware wallets on the market, often recommended for long-term bitcoin storage. The device emphasizes air-gapped operation and manual verification of transactions. However, no device is immune to implementation flaws. This incident is a reminder that even security-focused products can have subtle bugs that take years to surface.
The vulnerable firmware was distributed for a limited time, but many users likely created wallets during that window and continued to use them. A wallet created with a weak seed remains vulnerable regardless of later firmware updates. Patching the device does not change the private key that was already generated. Users who created keys during the affected period must migrate their funds to a newly-generated wallet on updated hardware or software.
Galaxy Research's Attribution Analysis
Galaxy Research believes that each wave of sweeps is the work of a single operator. The technical signatures, transaction timing, and wallet structures are consistent enough to suggest a common actor within each wave. However, the research team cannot determine whether the same attacker is behind all three waves.
The blockchain does not directly reveal coordination between different sweeps. Separate operators could be using the same tooling or following a shared playbook. Alternatively, one operator could be manually orchestrating all three waves while varying their methods to avoid detection. Galaxy Research notes that the evidence does not point decisively in either direction.
This uncertainty has practical implications. If different attackers are involved, then the vulnerability may be more widely known than previously assumed. If the same attacker is behind everything, then there may be a single operator with deep technical knowledge and a long-term strategy.
Why the Attack Is Notable
Cold-wallet attacks are relatively rare in bitcoin because the entire security model is built around keeping private keys offline. Most thefts occur through exchange hacks, phishing, or malware that compromises a hot wallet. An attack that reproduces private keys from a hardware device's weakness is more sophisticated and more concerning.
The attack is also notable for its longevity. The initial vulnerability was introduced in early 2021, and the first sweeps were observed well afterward. The fact that the attacker is still active and expanding the operation suggests that the vulnerability has not been fully mitigated across the bitcoin ecosystem. Many affected users may not even be aware that their wallets are at risk.
The scale of the losses also draws attention. Losing $89 million in bitcoin is a major event by any standard. For the individual victims, the losses are often life-changing. Unlike an exchange hack, where a centralized entity might offer reimbursements, this attack hits individual wallet owners directly. There is no customer support desk or insurance fund to recover the funds.
Risk to Existing Coldcard Users
Current Coldcard users who updated their firmware after the vulnerable release are not necessarily safe. The issue is not with the device's current operation but with the historical generation of seeds. Anyone who created a wallet using the March 2021 firmware could be affected, even if they later upgraded.
Galaxy Research's report does not identify specific vulnerable addresses publicly, but it highlights the importance of checking the age and generation method of hardware wallets. Users who suspect they may have been affected should move their bitcoin to a new wallet with a newly generated seed phrase. The old wallet should be abandoned permanently.
It is also worth noting that not every wallet created during the vulnerable period is automatically compromised. The weak randomness issue depended on specific device states and usage conditions. However, the risk is high enough that proactive migration is strongly recommended.
Impact on the Bitcoin Market
While the attack has caused significant losses for affected individuals, its broader market impact has been limited so far. The 1,367 bitcoin drained in the attacks represents a small fraction of the total bitcoin supply. Market prices have not shown a direct reaction to the news, and trading volumes remain within normal ranges.
Analysts have suggested that the attack could indirectly affect demand for regulated bitcoin exposure. Some investors may see the ongoing vulnerability as a reason to prefer institutional custody products rather than self-custody. Others may simply be reminded of the importance of using up-to-date hardware and verifying the integrity of their setup.
The attack also adds to a growing list of security incidents that highlight the risks of self-custody. While the ethos of bitcoin encourages users to control their own keys, incidents like this show that technical expertise is required to do so safely. A hardware wallet is only as secure as its implementation and the user's understanding of it.
What Bitcoin Holders Should Do
For anyone using a Coldcard device, the first step is to check which firmware version was used when the wallet was created. If it matches the vulnerable March 2021 release, the wallet should be considered at risk.
The safest action is to create a new wallet on a device with fully updated firmware and transfer all funds to the new address. This process should be done carefully, ideally using a secure and verified environment. After the transfer, the old wallet should not be used again.
More broadly, bitcoin holders should periodically review their security practices. This includes verifying that any hardware wallet is genuine, using strong and non-predictable entropy sources, and being cautious about firmware updates. It also means staying informed about reported vulnerabilities and acting quickly when warnings are issued.
The bitcoin community has long emphasized personal responsibility, but incidents like this reveal the limits of that philosophy. Even users who follow best practices can fall victim to a subtle flaw in a trusted device. The emergence of a third wave shows that the threat is not theoretical and that attackers are persistent.
As the investigation continues, the main unknown is whether the attacker will keep expanding the operation or move on. The shift to smaller balances suggests that the easy targets are diminishing. But the evolution of on-chain behavior also indicates a sophisticated operator who is willing to adapt. For the thousands of potentially affected addresses, the threat is far from over.
Source:Coindesk News
