Coldcard Firmware Vulnerability Exposes Over 4,500 Bitcoin Wallets
A vulnerability in a Coldcard firmware release from March 2021 has allowed attackers to systematically drain Bitcoin from thousands of wallets by reproducing keys generated with weak software-based randomness.
The attacks have swept nearly $89 million from 4,585 addresses, with losses totaling 1,367 Bitcoin. Galaxy Research believes each wave is the work of a single operator, but cannot determine if it's the same attacker behind all three waves.
The latest wave targets smaller balances and uses more complex, harder-to-trace transaction patterns. Each victim's coins are sent to its own destination rather than shared collector addresses, making it difficult to map the transactions.