Three Suspected Attacks Drain $88.6M from Coldcard-Generated Bitcoin Addresses

Share:
Attackers drained 1,367.05 BTC (≈$88.6M) from 4,585 Bitcoin addresses generated by Coldcard hardware wallets in three distinct waves — two early waves that hit about 3,200 addresses and moved roughly 1,000 BTC, and a later smaller wave — according to Galaxy Research on-chain analysis. The pattern points to a likely entropy/RNG weakness or supply-chain/side-channel exploit in address generation, posing systemic security and self-custody risks for crypto hardware wallets and prompting urgent firmware audits and user checks.
The revelation that attackers may have systematically drained Bitcoin addresses produced by Coldcard hardware wallets has put a harsh spotlight on cold storage assumptions. Galaxy Research’s on-chain work, detailed in the original report, identified three distinct waves siphoning a combined 1,367.05 BTC—valued around $88.6 million—across 4,585 addresses. The thefts span two patterns that look like a single operator, and a third that suggests either an upgraded method or a separate offender targeting the same vulnerable key space.
Coldcard hardware wallets are supposed to represent the gold standard of self-custody, using air-gapped signing and multiple layers of physical security. The idea that an attacker might drain funds without touching the physical device challenges the most basic promise of hardware wallets. While Galaxy’s analysis does not confirm the exact failure—whether it stems from insufficient entropy in key generation, a compromised supply chain, or a side-channel leak—the scale alone demands scrutiny.
What the Blockchain Footprint Shows
Galaxy’s researchers broke the thefts into two early waves that shared transaction structure and behavioral fingerprints, pointing to a common operator. Those waves hit 3,200 addresses and moved approximately 1,000 BTC. A third wave, noticeably smaller in per-transaction amounts and with different timing signatures, followed later. The divergence in technique could reflect a single attacker adjusting to new defenses, or an independent actor who recognized the same flaw and exploited it.
The data suggests the attacker did not need to interact with the wallet device or its PIN. Instead, the exploited addresses likely shared a weak point in how they were produced. Historically, poor random number generation has compromised everything from early Bitcoin wallets to blockchain signature schemes. If a Coldcard device—or the user environment around it—generated private keys with predictable entropy, an outside observer who identified the pattern could reconstruct keys and move funds at will.
Entropy Failures Remain a Recurring Nightmare
Hardware wallet security rests on two pillars: the physical isolation of the signing key, and the unpredictability of that key itself. Far too many exploits have bypassed the first pillar by breaking the second. In 2018, a weakness in the random number generation of certain ECDSA implementations led to key leaks across multiple blockchains. Hardware wallets that reuse compromised or low-entropy microcontrollers can produce addresses that a sophisticated attacker enumerates offline.
Coldcard’s approach uses a genuine random number generator and allows users to add their own entropy via dice rolls. Still, if the attack vector is tied to the address generation process rather than a firmware bug, the scope could extend beyond a single device model. The crypto industry has repeatedly learned that abstraction layers between the user and the cryptographic primitives hide fatal weaknesses. Galaxy’s caution that the root cause remains unconfirmed is not a hedge; it is an honest admission that on-chain forensics can only guess at the pre-chain moment of key creation.
While the immediate damage is already done—the 1,367 BTC is likely unrecoverable—the real cost will be measured in how users, wallet manufacturers, and auditors respond. A failure in entropy doesn’t just drain existing balances. It retroactively compromises all past and future addresses generated with the same flawed process, turning a single incident into a systemic risk for anyone who followed the same setup steps.
Market and Self-Custody Implications
The timing of this disclosure lands in a period when self-custody is being pushed harder by regulatory friction. The ongoing fight over landmark U.S. crypto legislation—covered in the ongoing regulatory standoff—could accelerate a shift toward non-custodial storage. If a widely trusted hardware wallet shows cracks, the political argument that users should hold their own keys weakens just when it matters most.
None of this diminishes the fundamental value of Bitcoin’s underlying network. The ecosystem continues to see robust developer participation, as shown by the latest developer activity rankings, with top protocols maintaining intense construction velocity. What changes is the calculus around how individuals store the product of that network. Hardware wallet security is not a solved problem; it is an ongoing arms race where each new generation of chips and entropy sources attempts to close the gaps that on-chain forensics will later uncover.
For the moment, the most practical question is whether affected Coldcard users have a way to check if their addresses were part of the drained set, and whether the manufacturer will clarify any firmware audit results. Galaxy’s decision to publish without a confirmed root cause is responsible but unsettling. It leaves open the possibility that other hardware wallets built on similar randomness assumptions could face the same threat, and that the $88.6 million drain is only the visible portion of a broader weakness.
Read More




