Bitcoin Cold-Wallet Attack Spreads: 4,500 Addresses Hit, Losses Near $89M

Galaxy Research flags a third wave of sweeps tied to weak Coldcard keys, targeting smaller balances and altering onchain fund collection.
VNIX Quick Take
- Attack on Bitcoin cold wallets expands to 4,500 addresses, with cumulative losses approaching $89 million.
- Galaxy Research identifies a third wave of sweeps linked to weak keys generated by Coldcard hardware wallets.
- The attacker now targets smaller balances and has changed how funds are collected onchain, complicating tracking.
Bitcoin Cold-Wallet Attack Widens: 4,500 Addresses Affected, Losses Near $89M
A wave of Bitcoin thefts targeting cold wallets has expanded dramatically, with Galaxy Research reporting that the attack has now spread to 4,500 addresses. Cumulative losses are approaching $89 million, marking one of the more significant security incidents in the crypto space this year.
The attack, which first came to light earlier this year, involves the unauthorized sweeping of funds from wallets that were thought to be secure because they were generated offline. Cold wallets, such as hardware devices, are typically considered the gold standard for storing Bitcoin securely, as they keep private keys offline and away from potential online threats.
However, this incident highlights a critical vulnerability: the quality of the random number generation used to create the private keys. If the keys are generated with insufficient entropy, they can be predicted or brute-forced by attackers. In this case, the attacker appears to have exploited weak keys that were generated by certain Coldcard devices, a popular brand among Bitcoin enthusiasts for its advanced security features.
What's Driving the Third Wave of Sweeps
Galaxy Research's latest analysis reveals that the attacker has initiated a third wave of sweeps, indicating a persistent and evolving threat. Unlike earlier phases that focused on larger balances, this new wave is targeting smaller amounts, potentially to avoid detection and to maximize the number of compromised wallets.
The attacker has also changed how funds are collected onchain. Earlier operations saw funds moved to a few centralized addresses, making it easier for blockchain analysts to track and potentially freeze. Now, the attacker is dispersing the stolen Bitcoin across a wider network of addresses, complicating efforts to trace and recover the funds.
Weak Keys: The Root of the Vulnerability
The root cause of this vulnerability lies in the random number generation process used by some Coldcard devices. If the device's firmware or hardware fails to generate truly random seeds, the resulting private keys can be mathematically related, making them susceptible to a 'birthday attack' or similar brute-force techniques. This is a known risk in the crypto hardware wallet industry, but it is rare in high-quality devices.
Galaxy Research has been monitoring the situation closely, and their findings suggest that the issue may be more widespread than initially thought. The expansion to 4,500 addresses indicates that many users may have been affected, and the true number could be higher as the attacker continues to sweep vulnerable wallets.
Changing Onchain Behavior
The attacker's shift in collection methods is also noteworthy. By using multiple intermediate wallets and mixing services, the attacker is making it harder for law enforcement and blockchain forensic firms to follow the money. This evolution in tactics suggests a sophisticated operator who is aware of common tracking techniques and is actively countering them.
For traders and investors, this serves as a stark reminder that even the most secure storage solutions are not infallible. It underscores the importance of using devices from reputable manufacturers, keeping firmware up to date, and regularly monitoring wallet activity for any unauthorized transactions.
Key Levels and Assets to Watch
While this news is primarily a security concern, it could have implications for Bitcoin's market dynamics. If the attacker begins to liquidate the stolen funds in large quantities, it could create selling pressure on exchanges, potentially impacting the price. Traders should monitor onchain data for any large transfers to exchanges, which could signal an imminent sell-off.
Additionally, this incident may affect the broader perception of hardware wallets, potentially driving demand for alternative security solutions. For those looking to understand market sentiment, keeping an eye on Bitcoin's price action around key support and resistance levels can provide clues. Technical analysis tools, such as moving averages and indicators, can help traders gauge the market's reaction to such news.
What This Means for Traders: Security and Market Implications
For traders, this incident is a reminder that security breaches can have ripple effects beyond the immediate victims. The potential for stolen funds to enter the market can create unexpected volatility. It is prudent to be aware of such events and to factor them into risk management strategies.
From a security standpoint, this is a call to action for all Bitcoin holders to review their own storage practices. Even if you don't use a Coldcard, the principle applies: ensure your private keys are generated with high entropy, and consider using multi-signature setups for large holdings. Regularly auditing your wallet addresses for any signs of unauthorized access is also a good practice.
If you're new to securing your own crypto, the classroom offers resources on best practices. For those looking to trade, using a regulated broker or exchange with robust security measures is essential. Broker accounts often provide additional layers of protection, such as insurance and advanced monitoring, which can mitigate some of the risks associated with self-custody.
In the broader context, this event highlights the ongoing cat-and-mouse game between security researchers and malicious actors. As the crypto ecosystem matures, such incidents will likely become less frequent, but they remain a real risk. Staying informed and adaptable is key to navigating this landscape.
In VNIX's view
The expansion of this attack to 4,500 addresses is a sobering reminder that no security solution is perfect. The attacker's shift to smaller balances and obscured onchain movements suggests a long-term, strategic operation that could continue to erode trust in self-custody. While the immediate market impact may be muted, the potential for future sell pressure from stolen funds is a factor to watch.
Educational analysis, not financial advice. Trading involves risk.
Trade smarter with VNIX indicators
Clear entry, exit and risk signals right on your TradingView chart.

