₿ Crypto

Bitcoin cold-wallet attack hits 4,500 addresses, losses near $89 million

A Bitcoin cold-wallet attack exploiting weak Coldcard-generated keys swells to 4,500 compromised addresses with losses approaching $89 million, as the attacker shifts to smaller balances and alters onchain collection methods.

🕐 1 min read

1 assets impacted (Crypto). Net bias: 0 Bullish, 1 Bearish, 0 Neutral. Strongest signal: BTC/USD ↓ 5/10 (75% confidence).

📊 Affected Assets (1)

BTC/USD
Bearish 🤖 75%
📅 Short-term 🌍 Global · Explicit

The attack directly impacts Bitcoin by compromising 4,500 addresses and draining nearly $89 million in BTC. Galaxy Research identified a third wave targeting smaller balances, signaling ongoing risk. The breach stems from weak Coldcard key generation, which could undermine trust in cold storage, potentially leading to downward price pressure if holders fear similar vulnerabilities.

Catalysts
  • Galaxy Research report of third-wave sweeps
  • Attacker targeting smaller balances and altering collection methods
Risk Factors
  • Stolen coins may be held or sold gradually, muting price impact
  • Market may view this as an isolated hardware issue rather than systemic
▼ Show FAQ (3) ▲ Hide FAQ
What does this attack mean for Bitcoin's price in the short term?

Stolen BTC could be sold on exchanges, creating selling pressure near resistance levels. The broader security breach may shake confidence among cold storage users, but the impact is likely limited to intraday volatility unless the attack escalates.

Should investors move their Bitcoin off Coldcard wallets?

Coldcard wallets using weak key generation are vulnerable, but the issue is tied to specific firmware versions. Users should verify their firmware and regenerate keys if affected, not necessarily abandon cold storage.

Is this attack unique to Bitcoin or could it affect other cryptocurrencies?

Currently, the attack is specific to Bitcoin because Coldcard is a Bitcoin-only hardware wallet. No other cryptocurrencies are directly affected.

🎯 Key Takeaways

  • A third wave of sweeps linked to weak Coldcard-generated keys has expanded the attack to 4,500 Bitcoin addresses.
  • Total losses near $89 million, with the attacker targeting smaller balances to evade detection.
  • The attacker changed onchain collection methods, suggesting evolving operational security.
  • Galaxy Research flagged the development, highlighting persistent cold-wallet risks.
  • The breach undermines confidence in offline wallet generation, potentially impacting cold storage adoption.
  • Users are urged to verify firmware and key generation methods for cold wallets.

📝 Executive Summary

Galaxy Research flagged a third wave of sweeps tied to weak Coldcard-generated keys, with the attacker now targeting smaller balances and changing how funds are collected onchain.

❓ FAQ

What is the Bitcoin cold-wallet attack?

The attack exploits weak random number generation in Coldcard hardware wallets, allowing an attacker to derive private keys and sweep funds from 4,500 addresses, with losses near $89 million.

How did the attacker change collection methods?

The attacker now targets smaller balances and uses altered onchain collection patterns to avoid triggering blockchain surveillance alerts.

What is Galaxy Research's role in this incident?

Galaxy Research identified and flagged the third wave of sweeps, providing onchain forensic analysis of the evolving attack.