Skip to content
Back to Guavy Wire
Crypto

Coldcard Firmware Vulnerability Exposes Over 4,500 Bitcoin Wallets

Instruments
BTC
Share

A vulnerability in a Coldcard firmware release from March 2021 has allowed attackers to systematically drain Bitcoin from thousands of wallets by reproducing keys generated with weak software-based randomness.

The attacks have swept nearly $89 million from 4,585 addresses, with losses totaling 1,367 Bitcoin. Galaxy Research believes each wave is the work of a single operator, but cannot determine if it's the same attacker behind all three waves.

The latest wave targets smaller balances and uses more complex, harder-to-trace transaction patterns. Each victim's coins are sent to its own destination rather than shared collector addresses, making it difficult to map the transactions.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Real-time market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc