Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million
A vulnerability in a March 2021 Coldcard firmware release has enabled attackers to systematically drain bitcoin from thousands of wallets by reproducing keys generated with weak software-based randomness. Three distinct waves of attacks have now swept 1,367 bitcoin—nearly…
Intelligence analysis by Llama

A vulnerability in a March 2021 Coldcard firmware release has enabled attackers to systematically drain bitcoin from thousands of wallets by reproducing keys generated with weak software-based randomness. Three distinct waves of attacks have now swept 1,367 bitcoin—nearly $89 million at recent prices—from 4,585 addresses.
Imagine you have a special kind of safe that stores your money. But someone found a way to make a copy of the key that unlocks the safe, so they can take all the money out without you even knowing. This is what happened to some people who used a special kind of safe called a Coldcard. Someone found a way to make a copy of the key, and now they are taking all the money out of these safes.
Analysis
A $60B Vote of Confidence
The recent attack on Coldcard-generated keys has highlighted the importance of secure key generation and the need for users to be cautious when using cold wallets. The attack, which has swept 1,367 bitcoin—nearly $89 million at recent prices—from 4,585 addresses, is a stark reminder of the risks associated with using vulnerable software-based randomness.
Why Cursor?
Galaxy Research has flagged a third wave of sweeps tied to weak Coldcard-generated keys, with the attacker now targeting smaller balances and changing how funds are collected onchain. The attacker working through Coldcard-generated keys is now emptying wallets worth a few thousand dollars each. Galaxy Research believes each wave is the work of a single operator, but cannot determine whether the same attacker is behind all three, as the blockchain does not reveal whether separate sweeps are coordinated.
The Road Ahead
The flaw traces to a March 2021 firmware build that routed seed generation to a predictable software randomiser instead of the chip’s hardware one, leaving a bounded set of possible keys that anyone with the disclosure and enough compute can reproduce offline, without ever touching a device. The sweeping has not stopped almost three days later, and the falling average haul says the profitable end of that key space is already picked over.
Key points
- A vulnerability in a March 2021 Coldcard firmware release has enabled attackers to systematically drain bitcoin from thousands of wallets.
- Three distinct waves of attacks have now swept 1,367 bitcoin—nearly $89 million at recent prices—from 4,585 addresses.
- The attacker working through Coldcard-generated keys is now emptying wallets worth a few thousand dollars each.
- Galaxy Research believes each wave is the work of a single operator, but cannot determine whether the same attacker is behind all three.
If the attacker is caught and the vulnerability is fixed, users can regain confidence in their cold wallets and the overall security of the bitcoin network.
The attack highlights the importance of secure key generation and the need for users to be cautious when using cold wallets. If the vulnerability is not fixed, users may continue to lose their funds, and the overall security of the bitcoin network may be compromised.



