Coldcard users face another wave of losses as 486 wallets were compromised in the latest Bitcoin theft targeting vulnerable, low-entropy addresses. This marks the fourth round of attacks exploiting weaknesses in Coldcard’s cold storage devices thought to be secure among Bitcoin maximalists.

Since the initial breach that affected around 500 wallets and drained over $70 million, the exploits have continued unabated. Long-term holders who left coins on dormant Coldcard wallets remain exposed, with attackers moving stolen funds through an expanding set of destination wallets. Recent analysis shows these intrusions have now reached multisig wallets, a worrying development for users relying on multi-signature security.

Data from Galaxy Research indicates that before this fourth wave, 1,196 addresses were hit, losing a total of 1,086.65 BTC. Despite warnings, as of August 3, many holders of various Coinkite wallet models have not secured their funds by transferring coins to freshly derived, safer wallets.

Coldcard had been popular among Bitcoin purists for its promise of secure, offline key storage. Yet, white hat hackers revealed that just minutes of AI processing can expose vulnerable Coldcard addresses, shaking the confidence in its security. On-chain researchers, including Alex Thorn from Firmwide Research, point out that the latest wave shows increased aggression and possibly targets multisig configurations, complicating the defense strategies further.

Market watchers continue to monitor the fallout closely. Bitcoin's price saw minimal immediate reaction following news of the latest breach but keep an eye on potential volatility as the attacks unfold.

This material is for informational purposes only and does not constitute financial advice.