A newly uncovered flaw in Coldcard hardware wallets has led to more than 1,367 BTC being stolen, amounting to roughly $88.6 million. The exploit targets how the wallet generates its secret recovery phrase, drastically lowering its randomness and opening the door for hackers to drain affected Bitcoin addresses.
Galaxy researchers monitoring the situation report three distinct waves of theft. The first two waves show similar theft patterns, funneling coins into common collector addresses and using specific Bitcoin output scripts. They occurred about 27 hours apart, involving thousands of victim addresses. However, the third wave runs differently. It avoids shared collectors, targets each victim separately, batches several victims per transaction, and uses different derivation paths, suggesting either a new attacker or an evolved strategy by the same one.
Most funds lost come from individual user wallets holding less than one BTC each, rather than institutional accounts. The vulnerability traces back to a firmware release on March 17, 2021, meaning any coins in these wallets created before that date were not affected.
This exploit has sparked urgency among Coldcard holders to secure their assets. Initial victim addresses were identified through reports on social media, enabling researchers to trace the on-chain theft patterns. Galaxy cautions that their data comes from analyzing blockchain data and unspent outputs, without computational confirmation that all flagged addresses were indeed compromised by the low entropy issue.
This article is for informational purposes and does not constitute financial advice.



