Fourth Wave of Coldcard Exploit Drains 389 BTC, Galaxy's Thorn Reports

Fourth Wave of Coldcard Exploit Drains 389 BTC, Galaxy's Thorn Reports

Alex Thorn, head of research at Galaxy, cautioned that pending transactions in the mempool could provide affected Coldcard users a brief window to rescue their cryptocurrency.

A fresh wave of systematic attacks targeting Bitcoin hardware wallets has emerged, with Coldcard users receiving urgent alerts about the latest round of thefts occurring merely days following the initial attack wave that took place on Thursday.

Through a post published on X this Monday, Alex Thorn, who serves as Galaxy's head of research, identified 218 separate transactions affecting 462 addresses belonging to possible victims over the course of recent hours, transferring approximately 388.9 Bitcoin (BTC) in total.

According to Thorn's analysis, the activity showed an average of 13.8 wallet sweeps occurring per block, representing roughly 45 times the frequency detected during a control period measured before the incident. The majority of these transfers have utilized a unique destination address created for each individual victim, rather than consolidating funds into a single centralized collection address.

A portion of the stolen funds have already been transferred into second hop addresses, according to his findings.

These are LIKELY Coldcard victims — they match the shape of coldcard vulnerable utxos and the elevated transaction pattern gives me high confidence they are another wave of attacks

Alex Thorn, Galaxy research head

The researcher indicated that comparable transactions are currently sitting in the mempool awaiting confirmation. Users who have been impacted and still maintain control of their associated keys might have the ability to submit a competing transaction featuring a higher fee structure to transfer their funds to a protected wallet before the attacker's pending transaction receives confirmation.

This latest activity comes in the wake of revelations concerning a previously unknown firmware vulnerability in Coldcard devices that resulted in affected hardware generating wallet seeds containing reduced entropy levels compared to what was intended. Current estimates indicate that more than 1,100 wallets have fallen victim to this exploit, resulting in the theft of $90 million worth of Bitcoin.

← Retour au blog