A firmware flaw in Coinkite's Coldcard hardware wallet has allowed attackers to systematically drain bitcoin from thousands of self-custody addresses, with losses now approaching $89 million across three distinct waves of theft. Galaxy Research, which has tracked the exploit since it first surfaced, said a third wave was flagged early Sunday and pushed the total to 1,367 BTC taken from 4,585 addresses.

The root cause traces back to a March 2021 Coldcard firmware release that routed seed phrase generation to a predictable software randomizer instead of the device's dedicated hardware randomizer. That change effectively shrank the pool of possible keys to a bounded, guessable set, letting attackers reproduce affected seed phrases without ever physically touching a victim's device.

woman using laptop
Photo by Christina @ wocintechchat.com M on Unsplash

Three Waves, Three Different Playbooks

According to Galaxy Research, the first wave moved 1,083 BTC out of 1,196 addresses on July 30 in just 41 minutes, funneling stolen coins toward a handful of shared collector addresses and processing victims one at a time. The pattern shifted noticeably by the third wave, which ran from Friday midday into Saturday morning UTC and pulled 208 BTC from 1,912 addresses.

That third wave looked more deliberate: funds were sent to separate destinations for each victim rather than pooled collector addresses, transactions used pay-to-witness-script-hash outputs instead of simple single-key outputs, and sweeps were batched roughly six victims at a time while scanning only the default derivation path. The average take per victim also fell sharply, from close to 1 BTC in the first wave to just over 0.1 BTC in the third, suggesting the attacker or attackers have moved on to smaller, previously overlooked balances.

Galaxy Research said it believes each wave likely represents a single operator, but cannot confirm whether the same party orchestrated all three, since on-chain analysis alone cannot distinguish a coordinated campaign from independent actors sweeping the same vulnerable key space.

Hardware Wallet Rivals Move to Reassure Users

The fallout quickly spread beyond Coinkite. Ledger said its Bitcoin wallets were not affected, pointing to its use of a 256-bit entropy system for seed generation. Trezor issued a similar assurance to its users.

Your funds are safe. The recent Coldcard issue is limited to their own custom firmware and how some of their devices generated randomness. Trezor does not share that code.

Coinbase CEO Brian Armstrong pointed to air-gapping keys as a security standard worth wider adoption, noting it is already how the exchange handles custody for its crypto ETF products. Elsewhere, Taproot Wizards' Udi Wertheimer argued the episode exposed how "worryingly unrealistic" self-custody expectations can be for average holders, warning that AI-assisted attacks are likely to make this kind of exploit more common rather than less.

Market Reaction

Bitcoin's price dipped nearly 3% to a two-week low of $62,400 following news of the exploit before recovering above $63,000. Santiment data showed market sentiment falling to a four-month low, a mood the firm compared to the caution seen during April's West Asia crisis escalation. Spot bitcoin ETFs also recorded roughly $265 million in net outflows on Friday as the story spread.