Coldcard Exploit Expands to 4,585 Wallets with $88.6M in BTC Untouched by Attacker

A Coldcard Mk4 hardware wallet device with a numeric keypad and digital screen

Quick Read

  • Galaxy Research linked the Coldcard exploit to 4,585 drained addresses across three waves.
  • A total of 1,367.05 BTC (.6 million) has been stolen from affected users.
  • The attacker has consolidated the funds into eight wallets, keeping 100% of the main stash unspent.
  • The exploit is tied to a firmware or seed-generation flaw in the Coinkite-manufactured hardware wallets.

A major security incident involving Coinkite’s Coldcard Bitcoin-only hardware wallets has expanded significantly, exposing critical vulnerabilities in long-term cryptocurrency storage. According to a recent analysis published by Galaxy Research, the suspected exploit has now compromised 4,585 addresses across three distinct waves of attacks, resulting in the cumulative theft of 1,367.05 BTC, valued at approximately $88.6 million.

The latest findings expand on earlier estimates of 2,673 affected wallets. In the most recent wave alone, the attacker drained 207.73 BTC from 1,912 addresses. Security researchers noted that the exploit appears linked to a critical firmware or seed-generation flaw in the Canadian-manufactured hardware wallet, which is widely trusted by investors for air-gapped, high-security Bitcoin storage.

Despite the massive scale of the theft, on-chain data shows the attacker has not yet liquidated the stolen assets. Onchain Lens reported that the compromised funds were consolidated into eight verified wallet addresses. Aside from a minor transfer of 0.06 BTC to a fresh address—likely a test transaction—roughly 1,159.35 BTC from the initial waves, and the subsequent stolen funds, remain entirely untouched.

This behavior suggests a highly coordinated operational strategy rather than opportunistic panic-selling. By holding the assets in consolidated clusters, the attacker maintains absolute control while avoiding immediate detection or freezing on regulated cryptocurrency exchanges.

For investigators, this prolonged inactivity provides a clear trail to monitor. However, the situation remains highly volatile. If the attacker attempts to route the funds through mixers or cross-chain bridges, the transaction trail will fragment, complicating blockchain tracking. Conversely, any attempt to transfer the Bitcoin to regulated exchanges with Know Your Customer (KYC) protocols could expose the attacker’s identity. Coinkite has urged affected users to replace their security keys, highlighting the ongoing maintenance risks associated with long-term Bitcoin custody.

|
Creator:Azat TV Editorial

LATEST NEWS