Coldcard Users Warned of Ongoing Theft Attacks
Bitcoin thefts tied to an entropy flaw in Coldcard hardware wallets are ongoing, according to Galaxy Research. The firm said that users holding funds in single-signature addresses created after the March 2021 firmware update should move their assets to a different address immediately.
The attacks began with sophisticated waves of large-scale thefts, which appear to have followed programmed patterns possibly using large language models. Most of the stolen Bitcoin remains frozen in attacker-controlled addresses and has not moved. Recently, smaller opportunistic attackers joined in, attempting to launder funds through THORChain and overseas casinos.
Galaxy Research found that most of the stolen assets belonged to long-term Bitcoin holders with an average dormancy period of 3.18 years. This suggests that losses were concentrated among users who kept their assets in self-custody rather than on crypto exchanges or in decentralized finance.