A devastating attack exploiting weak seed generation in older Coldcard hardware wallet firmware has expanded to nearly 4,500 addresses, with total losses approaching $89 million, according to research from Galaxy Digital.

The attack, which targets a vulnerability in a March 2021 Coldcard firmware build, has now gone through three distinct waves. The most recent, flagged early Sunday, drained approximately 208 bitcoin from 1,912 addresses between Friday and Saturday — a sharp departure from the earlier waves that targeted larger balances.

How the Attack Works

The vulnerability stems from a firmware build that routed seed generation through a predictable software-based random number generator instead of the device's hardware RNG. This left a bounded set of possible keys that an attacker with sufficient compute power could reproduce offline — without ever physically accessing a wallet.

The first wave, which struck on July 30, was the most aggressive: 1,083 bitcoin swept from 1,196 addresses in just 41 minutes, averaging nearly a full coin per victim. The second and third waves have progressively targeted smaller balances, suggesting the attacker is exhausting the vulnerable key space.

Evolving Tactics

The latest wave displays notably different operational security compared to earlier sweeps. Rather than consolidating stolen funds into a handful of collector addresses — a pattern that made the first two waves easy to map — wave three sends each victim's coins to individual destination addresses. It also parks them in pay-to-witness-script-hash outputs, a format that can carry multisignature or timelock conditions, further complicating tracing efforts.

The attacker has also shifted from processing one victim at a time to batching an average of six victims per sweep, and now scans only the default derivation path rather than testing multiple branches per seed.

Attribution Uncertainty

Galaxy Research has stated it is confident each wave represents the work of a single operator internally, but cannot confirm whether the same attacker is behind all three. The blockchain does not reveal whether separate sweeps are coordinated.

That ambiguity leaves two possibilities: either the original attacker is rebuilding operations after being publicly enumerated, or a second independent operator is grinding the same vulnerable key space.

Implications for Self-Custody

The scale of the attack has intensified debate about the reliability of hardware wallet security. Binance founder Changpeng Zhao publicly urged users to diversify across multiple wallets, acknowledging that even hardware-grade solutions can carry critical bugs.

The incident has also raised questions about whether self-custody has become too complex for everyday users. With losses now approaching $89 million across thousands of victims — many of whom held only modest balances — the attack underscores how a single firmware flaw can cascade into systemic losses across an entire hardware ecosystem.

Coldcard has not yet issued a public statement addressing the third wave of attacks. Users who generated seeds on affected firmware versions are urged to migrate their funds to wallets using verified hardware-based entropy.