Crypto Security Alert: Bitcoin Attack Hits 4,500 Addresses, Losses Near $89M

Quick Reads:
- Third wave drained 208 BTC from 1,912 addresses in under 24 hours
- Total losses across all waves: 1,367 BTC (~$89 million) from 4,585 addresses
- Root cause: a March 2021 Coldcard firmware bug that generated predictable keys
- Attacker now hides trails better, splitting funds instead of using shared collector wallets
A Bitcoin cold-wallet attack has spread further, with losses climbing toward $89 million across 4,585 addresses, according to a new report from Galaxy Research. What started as a single sweep just days ago has now evolved into a slow-burning, multi-wave heist that’s rattling confidence in one of crypto’s most trusted hardware wallets.
Galaxy Research flagged a third wave of sweeps early Sunday, with roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC. That’s a sharp drop from the opening wave, when the attacker was clearly hunting bigger fish.
The numbers tell the story of a hacker adjusting strategy on the fly. The third wave averaged just over a tenth of a bitcoin per victim, compared to the July 30 opening wave, which took close to a full coin, 1,083 bitcoin from 1,196 addresses in only 41 minutes. In other words, the attacker started by emptying the richest wallets first, then moved on to smaller balances once the low-hanging fruit was gone.
Combined, this Bitcoin cold wallet attack has now pulled 1,367 bitcoin, worth nearly $89 million, from 4,585 addresses, and the trail is getting harder to follow. Instead of funneling stolen coins into a handful of shared collector addresses, wave three sends each victim’s funds to its own separate destination, and stores them in pay-to-witness-script-hash outputs rather than the simpler single-key format used earlier. The attacker also began batching around six victims per sweep, compared to one at a time in the first wave, and narrowed the search to just the default key derivation path instead of checking multiple branches.
Analysts aren’t entirely sure if one person is behind everything. Galaxy Research believes each wave was likely carried out by a single operator, but cannot confirm whether the same attacker executed all three waves, since the blockchain doesn’t reveal whether separate sweeps are coordinated.
At the root of it all is an old software flaw. The vulnerability traces back to a March 2021 firmware update that routed key generation through a predictable software randomizer instead of the device’s built-in hardware randomizer, leaving a limited set of possible keys that anyone with knowledge of the flaw and enough computing power could reproduce offline, without ever touching a physical wallet.
Nearly three days after the first sweep, the attack still hasn’t stopped. The shrinking average haul suggests the most profitable wallets in that vulnerable key space have already been picked clean, but for the thousands of Coldcard users still holding funds generated during that firmware window, the risk hasn’t gone away yet.
The situation has already prompted warnings from industry figures. Binance founder CZ has publicly urged users to diversify across multiple wallets following the exploit, while further coverage details how the attack managed to compromise devices without any direct tampering.





