📝 Executive Summary
Galaxy Research flagged a third wave of sweeps tied to weak Coldcard-generated keys, with the attacker now targeting smaller balances and changing how funds are collected onchain.
A Bitcoin cold-wallet attack exploiting weak Coldcard-generated keys swells to 4,500 compromised addresses with losses approaching $89 million, as the attacker shifts to smaller balances and alters onchain collection methods.
The attack directly impacts Bitcoin by compromising 4,500 addresses and draining nearly $89 million in BTC. Galaxy Research identified a third wave targeting smaller balances, signaling ongoing risk. The breach stems from weak Coldcard key generation, which could undermine trust in cold storage, potentially leading to downward price pressure if holders fear similar vulnerabilities.
Stolen BTC could be sold on exchanges, creating selling pressure near resistance levels. The broader security breach may shake confidence among cold storage users, but the impact is likely limited to intraday volatility unless the attack escalates.
Coldcard wallets using weak key generation are vulnerable, but the issue is tied to specific firmware versions. Users should verify their firmware and regenerate keys if affected, not necessarily abandon cold storage.
Currently, the attack is specific to Bitcoin because Coldcard is a Bitcoin-only hardware wallet. No other cryptocurrencies are directly affected.
Galaxy Research flagged a third wave of sweeps tied to weak Coldcard-generated keys, with the attacker now targeting smaller balances and changing how funds are collected onchain.
The attack exploits weak random number generation in Coldcard hardware wallets, allowing an attacker to derive private keys and sweep funds from 4,500 addresses, with losses near $89 million.
The attacker now targets smaller balances and uses altered onchain collection patterns to avoid triggering blockchain surveillance alerts.
Galaxy Research identified and flagged the third wave of sweeps, providing onchain forensic analysis of the evolving attack.