A vulnerability tracing back to a March 2021 Coldcard firmware release has allowed an attacker to systematically drain bitcoin from thousands of self-custody wallets, with observed losses now approaching $89 million across three distinct waves of exploitation.
Galaxy Research, which has been tracking the sweeps, flagged a third wave early Sunday — roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC. That brings the cumulative total to 1,367 BTC taken from 4,585 addresses, based on Galaxy's onchain analysis.
The Vulnerability
The flaw stems from a firmware build that routed seed generation through a predictable software randomizer rather than the device's hardware-based random number generator. This left a bounded set of possible keys that anyone with knowledge of the vulnerability and sufficient computing power could reproduce offline — without ever physically accessing a Coldcard device.
In practice, the attacker can enumerate likely private keys from the vulnerable key space and sweep funds from any wallet whose seed was generated during the affected period. The devices themselves were never compromised; the weakness resides entirely in how certain seeds were created.
Three Waves, Three Strategies
The attacks have evolved with each wave, suggesting either an adaptive single operator or multiple actors exploiting the same vulnerable key space independently.
The first wave, launched on July 30, was the most aggressive: 1,083 bitcoin swept from 1,196 addresses in approximately 41 minutes, averaging close to one full coin per victim. Funds were consolidated into a handful of shared collector addresses, making the activity relatively easy to map.
The second wave followed a similar pattern but targeted a broader set of addresses.
By the third wave, the methodology had shifted significantly. Each victim's coins were sent to unique destination addresses rather than shared collectors, making aggregation far more difficult. The attacker also began parking funds in pay-to-witness-script-hash outputs — a format that can carry multisignature or timelock conditions — instead of the plain single-key outputs used previously. The average batch size increased to roughly six victims per sweep, compared to the one-at-a-time approach of wave one.
The falling average haul — roughly 0.1 BTC per victim in wave three versus nearly 1 BTC in wave one — suggests the most profitable portion of the vulnerable key space has already been exhausted.
Industry Response
The scale of the exploit has prompted renewed focus on hardware wallet security across the industry. Binance founder Changpeng Zhao publicly urged users to diversify their holdings across multiple wallets, acknowledging that hardware wallets can still contain bugs.
The incident has also reversed a post-FTX trend. Following the exchange's collapse in late 2022, users moved funds off exchanges and into self-custody. The Coldcard exploit has driven a countervailing movement, with smaller bitcoin holders transferring funds back onto exchanges perceived as having institutional-grade security, according to blockchain analytics firms.
What Affected Users Should Do
Anyone who generated a wallet seed using a Coldcard device running the affected March 2021 firmware should treat those wallets as compromised. Funds should be moved immediately to a new wallet generated with unaffected firmware or a different hardware wallet entirely.
Coldcard has not yet issued a formal statement on the third wave of exploits. Galaxy Research noted that it is confident each wave represents a single operator internally but cannot determine whether the same attacker is behind all three, as blockchain data alone cannot establish coordination between separate sweeps.
The incident underscores a sobering reality for self-custody: the security of a hardware wallet depends not just on the physical device but on every line of firmware it has ever run.