discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million

A vulnerability in a March 2021 Coldcard firmware release has enabled attackers to systematically drain bitcoin from thousands of wallets by reproducing keys generated with weak software-based randomness. Three distinct waves of attacks have now swept 1,367 bitcoin—nearly…

By Shaurya Malwa·Aug 1·coindesk.com·2 min read

Intelligence analysis by Llama

Hacker facing screens with lines of code (Boitumelo/Unsplash)
Hacker facing screens with lines of code (Boitumelo/Unsplash)Image: coindesk.com

A vulnerability in a March 2021 Coldcard firmware release has enabled attackers to systematically drain bitcoin from thousands of wallets by reproducing keys generated with weak software-based randomness. Three distinct waves of attacks have now swept 1,367 bitcoin—nearly $89 million at recent prices—from 4,585 addresses.

Why it matters

The attack highlights the importance of secure key generation and the need for users to be cautious when using cold wallets.

Imagine you have a special kind of safe that stores your money. But someone found a way to make a copy of the key that unlocks the safe, so they can take all the money out without you even knowing. This is what happened to some people who used a special kind of safe called a Coldcard. Someone found a way to make a copy of the key, and now they are taking all the money out of these safes.

Analysis

A $60B Vote of Confidence

The recent attack on Coldcard-generated keys has highlighted the importance of secure key generation and the need for users to be cautious when using cold wallets. The attack, which has swept 1,367 bitcoin—nearly $89 million at recent prices—from 4,585 addresses, is a stark reminder of the risks associated with using vulnerable software-based randomness.

Why Cursor?

Galaxy Research has flagged a third wave of sweeps tied to weak Coldcard-generated keys, with the attacker now targeting smaller balances and changing how funds are collected onchain. The attacker working through Coldcard-generated keys is now emptying wallets worth a few thousand dollars each. Galaxy Research believes each wave is the work of a single operator, but cannot determine whether the same attacker is behind all three, as the blockchain does not reveal whether separate sweeps are coordinated.

The Road Ahead

The flaw traces to a March 2021 firmware build that routed seed generation to a predictable software randomiser instead of the chip’s hardware one, leaving a bounded set of possible keys that anyone with the disclosure and enough compute can reproduce offline, without ever touching a device. The sweeping has not stopped almost three days later, and the falling average haul says the profitable end of that key space is already picked over.

Key points

  • A vulnerability in a March 2021 Coldcard firmware release has enabled attackers to systematically drain bitcoin from thousands of wallets.
  • Three distinct waves of attacks have now swept 1,367 bitcoin—nearly $89 million at recent prices—from 4,585 addresses.
  • The attacker working through Coldcard-generated keys is now emptying wallets worth a few thousand dollars each.
  • Galaxy Research believes each wave is the work of a single operator, but cannot determine whether the same attacker is behind all three.
The Upside

If the attacker is caught and the vulnerability is fixed, users can regain confidence in their cold wallets and the overall security of the bitcoin network.

The Downside

The attack highlights the importance of secure key generation and the need for users to be cautious when using cold wallets. If the vulnerability is not fixed, users may continue to lose their funds, and the overall security of the bitcoin network may be compromised.

Originally reported at

coindesk.com

Discernion covers the story. Read the full piece at the source.

Tagscryptocold-walletattackbitcoinsecurity

Author

Shaurya Malwa

Intelligence analysis by

Llama

Published

Aug 1, 2026

Source

coindesk.com

Share

Topics

cryptocold-walletattackbitcoinsecurity

Related

More from this desk

Aug 1·cointelegraph.com

Onchain, In Court: What Happened In Crypto Legal News This Week

A case tied to defunct crypto exchange FTX moves forward, a soldier seeks to dismiss over a Polymarket bet and a former congressman was ordered to pay $35,000 for manipulative trading.

Aug 1·cointelegraph.com

Minnesota Crypto ATM Ban Goes into Effect After Reported $1M Losses

Minnesota crypto ATM ban takes effect after reported $1M losses from scams.

A pair of hands resting on a keyboard with an iPad showing graphs and price quotes. (Kanchanara/Unsplash)
Aug 1·coindesk.com

Tokenized stock trading surged 288% in July, but one QQQ token drove most of it

Tokenized stock trading reached a record $11.3 billion in July, a 288% increase, driven primarily by a single QQQ-tied token on Binance, which accounted for 82% of that volume.

hacking money Binance bitcoin Breaking Push changpeng zhao cryptocurrency cz
Aug 1·decrypt.co

CZ Warns Bitcoin Holders After $70 Million Wallet Exploit: 'Nothing Is 100%'

Binance founder Changpeng 'CZ' Zhao is warning crypto owners not to place blind faith in hardware wallets, following an exploit that drained tens of millions of dollars in Bitcoin from users. The exploit, which occurred due to a firmware build error in a March 2021 Coldca…