A wallet-draining attack tied to a years-old firmware flaw has now hit 4,585 Bitcoin addresses across three separate waves, with total losses climbing to roughly 1,367 BTC, nearly $89 million.
If you saw headlines mentioning “1,200 addresses,” that was just the first wave; the number has grown fast since.
The Root Cause: A 2021 Firmware Flaw in Coldcard Wallets
The issue traces back to a March 2021 firmware release for Coldcard, a popular hardware cold wallet.
That version generated private keys using a predictable software randomizer instead of the device’s built-in hardware randomness.
As a result, anyone who knew about the flaw and had enough computing power could recreate the same keys without ever accessing the physical device.
It’s a sharp reminder that cold storage is only as safe as the software behind it, not automatically bulletproof just because it’s offline, a key takeaway when analyzing wallets vs exchanges in terms of self-custody security.
Three Waves, Three Different Attack Patterns
The first wave hit hardest and fastest: 1,083 BTC drained from 1,196 addresses in just 41 minutes on July 30, averaging almost a full coin per victim.
A second wave followed, and by the third wave, spotted by Galaxy Research early Sunday, the attacker was going after much smaller balances, about a tenth of a BTC per address, with third wave using a different tactic.
Instead of sending stolen funds to shared collection wallets, the attacker sent them to separate destinations, combined multiple victims into single transactions, and used a more complex transaction structure that made the funds harder to track on the blockchain.
Galaxy Research believes each wave was carried out by a single operator, although it cannot confirm whether all three waves were the work of the same attacker.
Why the Method Matters More Than the Wallet Brand
This wasn’t a hack of Coldcard’s servers or a stolen device; it was a predictable-key problem baked into old firmware.
The incident also serves as a reminder to review basic wallet security habits, such as keeping your hardware wallet firmware up to date, since vulnerabilities like this can remain undiscovered for years before being exploited at scale.
The CryptoBreakers Take: The scariest part isn’t the dollar figure; it’s that this bug sat quietly for over four years before being exploited. If you’re using an older hardware wallet, it’s worth checking for firmware updates sooner rather than later.
This article is provided for informational purposes only and does not constitute financial or cybersecurity advice. Always verify your wallet’s firmware status directly through the manufacturer’s official resources.
Source: Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million

