Galaxy Research has identified a third wave of attacks exploiting weak Coldcard-generated keys, with the attacker now focusing on smaller amounts and altering fund collection methods on the blockchain.
By Shaurya Malwa Aug 1, 2026, 8:10 p.m. 2 min readMake preferred on ShareShare this articleCopy linkX (Twitter)LinkedInFacebookEmailMake preferred on Hacker facing screens with lines of code (Boitumelo/Unsplash)SummaryShow- A flaw in a Coldcard firmware update from March 2021 has allowed hackers to methodically deplete bitcoin from numerous wallets by replicating keys produced with insufficient software randomness.
- Three separate attack waves have collectively taken 1,367 bitcoin—valued at nearly $89 million—across 4,585 addresses, with the most recent wave concentrating on smaller balances and employing more intricate and less traceable transaction methods.
- Galaxy Research posits that each wave is orchestrated by a single operator, but cannot confirm whether all three are executed by the same individual, as the blockchain does not clarify if the sweeps are coordinated.
The hacker exploiting Coldcard-generated keys is now targeting wallets containing thousands of dollars.
Galaxy Research noted a third wave of attacks early Sunday, with approximately 208 bitcoin drained from 1,912 addresses between Friday afternoon and Saturday morning UTC.
This averages just over a tenth of a bitcoin per victim, compared to the first wave on July 30, which averaged nearly a full coin, with 1,083 bitcoin taken from 1,196 addresses in just 41 minutes.
Overall losses from all three waves have now reached 1,367 bitcoin, nearly $89 million, from 4,585 addresses.
The latest wave sends each victim’s coins to individual destinations, in contrast to the first two waves where funds were pooled into a few shared addresses, making them easier to trace. It also utilizes pay-to-witness-script-hash outputs, which can include multisignature or timelock conditions, rather than the simpler single-key outputs used previously.
This wave grouped an average of six victims per sweep, compared to the first wave, which targeted one victim at a time, and it only scanned the default derivation path—the primary branch of the key tree wallets check first—rather than exploring multiple branches for each seed.
This could imply either the same operator adjusting tactics after being identified publicly or a different one working independently within the same vulnerable key space, as the blockchain does not differentiate between them.
Galaxy expressed confidence that each wave is the work of a single operator but will not connect the three waves.
The vulnerability stems from a March 2021 firmware release that directed seed generation to a predictable software randomizer rather than the hardware one, resulting in a limited set of potential keys that can be reproduced offline by anyone with the knowledge and computational resources, without needing access to the device.
Despite almost three days passing, the sweeping has continued, and the declining average haul suggests that the profitable part of that key space has already been largely exploited.
Latest Crypto News- 1Tokenized stock trading surged 288% in July, but one QQQ token drove most of it4 hours ago
- 2Bank of Italy research suggests stablecoins aren't necessarily cheaper for remittances5 hours ago
- 3SEC to review Nasdaq bitcoin options approval after CME challenge5 hours ago
- 4Solana Foundation's new CISO warns AI is making crypto scams more convincing8 hours ago
- 5Everyone has the perps convergence backwards8 hours ago
- 6Binance founder CZ calls for wallet diversification after $70 million Coldcard exploit11 hours ago
- 7XRP Ledger upgrade brings back features once pulled over critical bugs14 hours ago
- 8How bitcoin cold wallets lost $70 million in an attack that never touched the devices15 hours ago
- 9Bitcoin holds monthly gain, faces 'choppy' August as 'forced-selling' exhausted, analysts sayJul 31, 2026
- 10Tether posts $1.5 billion operating profit in Q2 as reserve buffer falls by halfJul 31, 2026
The Evolution of the Crypto CEX Landscape: A Case Study on Binance
The Evolution of the Crypto CEX Landscape: A Case Study on Binance
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
By CoinDesk ResearchJun 29, 2026Commissioned byBinanceBinance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
Why it matters:
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
View Full ReportMore From Tech