Galaxy Research says a vulnerability in Coinkite's Coldcard hardware wallet has led to 1,596 Bitcoin stolen from about 7,300 addresses across three confirmed attack waves. The estimate could climb to roughly 2,055 BTC, worth nearly $130 million, if a suspected fourth wave is verified. Coinkite has traced the flaw to a 2021 firmware change and shipped patches, but existing wallet seeds generated on vulnerable devices remain exposed.
The research firm has confirmed 1,596 Bitcoin stolen from about 7,300 addresses across three attack waves tied to the Coldcard vulnerability. The firm said in a post published Monday on X the total could rise to about 2,055 BTC — nearly $130 million — if a suspected fourth wave is confirmed.
Fourth wave still under review
Galaxy said blockchain activity suggests the suspected fourth wave is "substantially comprised of" one attacker, giving analysts medium-high confidence despite lingering uncertainty over which wallets were hit. Alex Thorn, Galaxy's head of firmwide research, first flagged the fourth wave on Aug. 3, and his estimate later rose to 448.7 BTC from 709 potential victim addresses, though blockchain data alone cannot confirm every victim.
Flaw traces back to a 2021 firmware change
Coinkite disclosed last week that the vulnerability originated in March 2021, when it integrated a new cryptographic library into the firmware. Instead of drawing wallet seeds from the device's hardware-backed random-number generator, the firmware relied on a deterministic pseudo-random generator supplied by MicroPython.
The flaw affects seeds generated on Coldcard Mk3, Mk4, Mk5 and Coldcard Q devices running vulnerable firmware. Coinkite estimates affected Mk2 and Mk3 devices may carry roughly 40 bits of effective entropy, while vulnerable Mk4, Mk5 and Coldcard Q models generate roughly 72 bits instead of the intended 128.
Most stolen Bitcoin remains untouched
Galaxy said about 90% of the stolen Bitcoin has not moved, and none of the coins taken during the first three confirmed waves have moved since the theft. Investigators have shared confirmed attacker and victim addresses with U.S. law enforcement agencies, cryptocurrency exchanges and cyber investigation groups. Attack activity accelerated to about 13.8 wallet sweeps per Bitcoin block during the suspected fourth wave, compared with roughly 0.3 sweeps per block before the incident.
Coinkite urges wallet migration
Coinkite has released firmware updates for every affected product, including version 4.2.0 for Mk2 and Mk3, version 5.6.0 for Mk4 and Mk5, version 1.5.0Q for Coldcard Q, and Edge releases 6.6.0X and 6.6.0QX, and it has destroyed its remaining inventory carrying vulnerable firmware. Installing the new firmware protects only wallets created after the fix; existing seed phrases generated on vulnerable devices remain exposed and should be replaced. Coinkite recommends generating a new seed after updating, verifying a receiving address, sending a small test transaction, then moving the remaining balance once that test succeeds.
The company added that wallets created using at least 50 fair private dice rolls are not exposed by this hack alone, though it still recommends migration because the original vulnerable seed remains weak.
Source: crypto.news
Trading involves risk.