The safest way to store bitcoin just failed. A cold wallet attack targeting Coldcard-generated keys has swept 4,500 addresses for close to $89 million, according to Galaxy Research. The attacker is still working.
Key Takeaways
- Galaxy Research flagged a third wave of sweeps: 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC
- The attacker shifted tactics — now targeting wallets holding just over a tenth of a bitcoin each, not high-value accounts
- The vulnerability is in Coldcard's key generation process, breaking the security model before users ever go online
What Happened
Galaxy Research confirmed a third wave of bitcoin sweeps early Sunday, according to CoinDesk reporting. The firm tracked roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC. All targeted wallets were generated using Coldcard hardware devices.
The attack pattern changed. Earlier waves may have focused on larger balances. Now: wallets worth a few thousand dollars each — just over a tenth of a bitcoin per victim. That shift matters. It means the vulnerability isn't limited to whales. It's systemic.
Galaxy Research noted the attacker changed how funds are collected onchain. The tactical shift suggests adaptation — possibly to avoid detection patterns or to work through a broader set of vulnerable addresses more efficiently.
The Security Model That Broke
Cold wallets are supposed to be the end of the conversation. Keep your keys offline, store them on dedicated hardware, never expose them to a networked device. For years, that advice has been repeated as gospel across bitcoin communities, exchanges, and custody providers.
This attack breaks the model before the user ever connects to the internet. The vulnerability sits in how Coldcard generated certain private keys. If the randomness is weak — if the key generation process itself is flawed — the hardware's offline status is irrelevant. The keys were compromised at creation.
What most coverage misses: this isn't a phishing attack, a malware infection, or a user error story. The users followed best practices. They bought hardware wallets specifically marketed as cold storage. They generated keys offline. They did everything right. The supply chain failed them.
What Is Not Yet Known
The available reports do not specify which Coldcard firmware versions are affected. CoinDesk's article does not include a statement from Coinkite, the manufacturer, addressing the vulnerability or advising users on remediation. There is no indication whether a patch exists or whether affected users have been notified directly.
The source does not clarify the root cause — whether this stems from a software bug, flawed entropy generation, or another technical flaw in the key creation process. It also does not specify the timeframe during which vulnerable keys were generated, making it difficult for users to assess whether their wallets are at risk.
The 4,500 affected addresses may represent all vulnerable wallets, or only those already swept. The article does not indicate whether additional waves are expected or if the attacker's list of targets is exhausted. Galaxy Research's methodology for detecting the pattern is not detailed, and there is no mention of law enforcement involvement or fund recovery efforts.
What Investors Should Watch
Coinkite's next public statement. Users need to know which firmware versions generated weak keys, whether a fix is available, and how to verify if their addresses are affected. The source material does not indicate whether such a verification tool exists.
Galaxy Research may publish further analysis showing whether new sweep waves continue. Blockchain analytics firms tracking the stolen funds could reveal consolidation patterns, mixing activity, or cashout attempts — all of which would indicate the attacker's next moves.
For holders using Coldcard wallets generated during the affected period, the question is whether to rotate keys now or wait for official guidance. Rotating early means transaction fees and operational friction. Waiting risks being in the next wave. The source does not provide enough information to make that call confidently.
Why It Matters
This attack exposes a supply chain trust problem in cryptocurrency hardware. Cold wallets are sold as the safest option for bitcoin storage — but if key generation is flawed at the hardware or firmware level, offline security fails before the user ever takes custody. Investors should verify which wallet versions are affected and consider whether keys generated during the vulnerable period need to be rotated. For broader context on tracking blockchain security events, see NWCast's guide to building a volatility tracker with yfinance historical data for monitoring market reactions to security incidents.