A vulnerability in a March 2021 Coldcard firmware release is still draining bitcoin from wallets generated on that build, with Galaxy Research flagging a third wave of sweeps early Sunday that pulled roughly 208 BTC from 1,912 addresses between Friday midday and Saturday morning UTC. Across all three observed waves, attackers have now drained 1,367 BTC, close to $89 million at recent prices, from 4,585 addresses.
The third wave looks different from the first two onchain. Each victim's coins are routed to a separate destination rather than the handful of shared collector addresses that made waves one and two easy to map, and the proceeds are parked in pay-to-witness-script-hash outputs, a format capable of carrying multisignature or timelock conditions, rather than the plain single-key outputs used before. Wave three also batches an average of six victims per sweep where the July 30 opening wave emptied one address at a time, and it scans only the default derivation path instead of testing several branches per seed, behaviour Galaxy reads as the operator rebuilding after public enumeration.
Why it matters
The flaw traces to a March 2021 firmware build that routed seed generation to a predictable software randomiser instead of the chip's hardware one, leaving a bounded set of possible keys that anyone with the disclosure and enough compute can reproduce offline, without ever touching a device. Wallets created on that build remain vulnerable regardless of where they sit today; the attacker does not need access to the hardware, only to the published weakness. The falling average haul per victim, from nearly a full coin in the opening wave to roughly a tenth of a bitcoin in wave three, says the profitable end of that key space is already picked over.
Market impact
Galaxy says it is confident each wave is internally one operator but will not link the three to a single actor, because the chain does not distinguish whether the later sweeps are the same person rebuilding or a second party grinding the same vulnerable key space independently.
Frequently asked questions
-
What is the Coldcard March 2021 firmware vulnerability?
It was a build that routed seed generation to a predictable software randomiser instead of the chip's hardware one, leaving a bounded set of possible keys. Anyone with the disclosure and enough compute can reproduce those keys offline, without ever touching the device.
-
How much bitcoin has been stolen across all three waves?
Galaxy Research observed 1,367 BTC, close to $89 million at recent prices, drained from 4,585 addresses across the three waves combined.
-
How is the third wave different from the first two?
Wave three routes each victim's coins to a separate destination rather than shared collector addresses, parks proceeds in pay-to-witness-script-hash outputs, and batches an average of six victims per sweep instead of one. Average haul per victim has fallen from nearly a full coin to about a tenth of a bitcoin.
-
Is the same attacker behind all three waves?
Galaxy says it is confident each wave is internally one operator, but will not link the three to a single actor. The blockchain does not reveal whether the later sweeps are the same person rebuilding after public enumeration or a second party grinding the same key space independently.
-
Who remains exposed and what should they do?
Any user who generated a seed on the affected March 2021 Coldcard firmware build and still holds balance on that wallet remains vulnerable. The attacker does not need the hardware, only the published weakness, so affected users should move funds to a new seed generated on patched firmware or hardware.
CoinDesk