Doctorcrypto About RSS Subscribe
Doctorcrypto
HomeOpinion › Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million
Opinion

Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million

By Malik Sokolov · · 2 min read

A sophisticated attack targeting Bitcoin cold wallets has now compromised roughly 4,500 addresses, with cumulative losses approaching $89 million, according to fresh analysis from Galaxy Research. The findings point to a third wave of thefts linked to weak private keys generated by certain Coldcard hardware wallet setups.

How the Attack Is Unfolding

Galaxy Research flagged the latest surge as an escalation of a campaign that has been draining funds from vulnerable wallets in successive waves. The attacker appears to be exploiting keys that were produced with insufficient randomness, leaving them susceptible to being guessed or reconstructed by anyone with the right tools.

In this most recent phase, the perpetrator has shifted tactics, going after wallets holding smaller balances rather than concentrating solely on high-value targets. The methodology for consolidating stolen coins on the blockchain has also changed, suggesting the attacker is refining an already efficient operation.

Nearly 4,500 addresses have been swept clean, with the damage now closing in on $89 million.

Why Cold Wallets Were Vulnerable

Cold wallets are typically viewed as the gold standard for securing cryptocurrency because they keep private keys offline and out of reach of remote hackers. But the security of any wallet ultimately rests on the strength of the keys it generates. When those keys are created with flawed entropy, the offline advantage evaporates.

The vulnerability appears tied to how some keys were produced during specific Coldcard-related processes. Weak or predictable key generation gives attackers a mathematical opening to recover the private keys and sweep the associated funds without ever needing physical access to the device.

Key takeaways from the ongoing incident include:

  • Losses have climbed toward $89 million across three identified waves.
  • Roughly 4,500 addresses have been affected so far.
  • The attacker is now pursuing smaller balances and altering onchain collection methods.

What Holders Should Watch For

Users who generated keys through affected setups are being urged to move their assets to freshly created, securely generated wallets as a precaution. The evolving nature of the attack, from targeting whales to sweeping smaller holdings, signals that no balance may be too small to be at risk.

The incident serves as a stark reminder that hardware security alone does not guarantee safety if the underlying key generation is compromised. As the campaign continues, researchers are

Was this useful?👍 Yes👎 No