ADVERTISEMENT

Events

IAMTN Annual Summit 2026
14 Oct 26
London
Money20/20 USA 2026
18 Oct 26
Las Vegas

Galaxy Research Flags Fourth Attack Wave Sweeping 389 BTC From Coldcard Wallets

Galaxy Research head of firmwide research Alex Thorn has identified a fourth wave of automated wallet drains targeting legacy Coldcard hardware wallet users, with attackers sweeping roughly 389 Bitcoin worth over $25 million across blocks 960,778 to 960,792.

The operation executed 218 transactions across 462 addresses, showing a 45-fold increase in normal network sweep rates. Investigators noted a 1:1 victim-to-destination address setup, with affected wallets showing zero prior input activity before being drained.

The ongoing exploits came from a design flaw introduced in Coldcard firmware versions 4.0.1 through 4.1.9 in March 2021. The bug bypassed the hardware random number generator during seed phrase creation, producing predictable private keys that attackers can easily enumerate and drain across four distinct attack waves, hackers have stolen roughly 1,367 Bitcoin, valued at nearly $89 million, from thousands of unmigrated dormant addresses.

Why dormant Coldcard wallets are still at risk

The vulnerability mainly threatens long-term holders who created seed phrases on affected firmware versions and never migrated their funds to newly generated seeds. Because the flaw affects seed generation instead of device encryption, updating the firmware on an old device does not protect previously exposed keys.

Bitcoin seed phrases and keys established on Coldcard hardware, specifically the Mk3, Mk4, Mk5, and Q models, without utilizing manual dice-roll entropy or secondary passphrases are compromised and need urgent replacement.  To reduce this threat, Nunchuk advises using Slipstream to route transactions directly to reputable mining partners like MARA, ensuring transaction privacy until on-chain confirmation.  

Law enforcement continues to advance its track record with dormant assets

The incident shows a testing gap in the industry around entropy generation in cold storage hardware. While public-key encryption remains mathematically secure, weaknesses in seed generation can still leave even offline devices vulnerable to remote recovery. 

Meanwhile, DeFi Planet previously reported that Irish police have successfully recovered €35 million from a dormant Bitcoin wallet belonging to Clifton Collins. Collins, a former drug dealer, originally lost access to his fortune after the private keys, which were written on a piece of paper, were reportedly thrown away by his landlord.

The Criminal Assets Bureau (CAB) managed to bypass the security of the 12 separate accounts that had remained untouched for years. This recovery became one of the largest seizures of digital assets in Irish history, showing the efforts of law enforcement to track illicit crypto funds.

 

Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights

Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.

ADVERTISEMENT
ADVERTISEMENT

Spotlight

-
00:00
00:00
Update Required Flash plugin
-
00:00
00:00