
Galaxy researchers identified three waves of attacks draining 1,367 BTC from Coldcard wallets. The exploit stems from a 2021 firmware bug that weakened entropy. Victims are mostly individual self-custody holders.
Alpha Score of 58 reflects moderate overall profile with strong momentum, poor value, moderate quality, strong sentiment.
Crypto researchers say Bitcoin investors have lost more than $88.6 million to an exploit in the Coldcard hardware wallet.
Galaxy researchers said funds are being drained from addresses in waves because of a firmware bug that slashed the randomness of how the wallet creates its secret recovery phrase. The vulnerable code shipped on March 17, 2021, around block 674,951. None of the coins identified in the three attack waves were created before that block, the researchers noted.
The researchers identified a third wave hitting 207.7 BTC. The first two waves shared the same funnel topology into a handful of shared collector addresses, the same P2WPKH destination types, and the same mix of derivation paths. Those waves came 27 hours apart. Galaxy said treating them as one operator is reasonable but rests on resemblance, not proof. The two waves already differ in fee constants and whether the sweeps signal replace-by-fee.
Wave 3 differs on every behavioral axis the researchers could measure. It abandons the shared collector for one destination per victim, it holds in P2WSH rather than P2WPKH, it batches an average of 6.37 victims into each sweep where wave 1 took exactly one, and it scans only the default derivation path.
"It may be the same actor with rebuilt tooling – the anti-clustering design is exactly the evolution one would predict after waves 1 and 2 were enumerated – or it may be a second actor working the same vulnerable key space independently, which the published disclosures make entirely feasible. The chain does not distinguish these, nor can we," the researchers wrote.
Across all three waves, Galaxy identified 1,367.05 BTC drained from 4,585 addresses. The loss profile is dominated by sub-1 BTC addresses in count but by larger addresses in value. The researchers said this looks like the shape of individual self-custody, not institutional holdings.
The theft has triggered a scramble among Coldcard users to protect their funds. Galaxy said some initial addresses came from victim reports on X and were used to map the on-chain patterns.
The researchers warned that their findings are derived solely from analyzing Bitcoin block data and the unspent-output set. They have not used computation to confirm whether the addresses identified as possible victims were actually generated with low entropy.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.