A vulnerability in a March 2021 Coldcard firmware release has enabled attackers to systematically drain bitcoin from thousands of wallets by reproducing keys generated with weak software-based randomness. Galaxy Research flagged a third wave of sweeps early Sunday, bringing observed losses across all three waves to 1,367 bitcoin, nearly $89 million at recent prices, from 4,585 addresses. The attacker is now emptying wallets worth a few thousand dollars each, a signal that the profitable end of the vulnerable key space may already be picked over.
The three waves
The July 30 opening wave averaged close to a full coin per victim, moving 1,083 bitcoin from 1,196 addresses in 41 minutes. A second wave followed, though Galaxy did not break out its standalone totals. The third wave, recorded between Friday midday and Saturday morning UTC, drained roughly 208 bitcoin from 1,912 addresses, just over a tenth of a bitcoin per victim. The declining average haul suggests the attacker is working through progressively smaller balances.
Changing onchain patterns
Wave three sends each victim’s coins to its own destination rather than the handful of shared collector addresses that made the first two waves easy to map. It parks the funds in pay-to-witness-script-hash outputs, a format that can carry multisignature or timelock conditions, instead of the plain single-key outputs used before. It also batched an average of six victims into each sweep where wave one took exactly one at a time, and scanned only the default derivation path, the standard branch of the key tree a wallet checks first, instead of testing several branches per seed.
One operator or several
Galaxy said it is confident each wave is internally the work of a single operator, but the blockchain does not reveal whether separate sweeps are coordinated. That leaves two possibilities: the same operator rebuilding after being enumerated in public, or a second one grinding the same vulnerable key space independently. The chain does not distinguish them, and Galaxy will not link the three.
The flaw and what remains
The flaw traces to a firmware build that routed seed generation to a predictable software randomiser instead of the chip’s hardware one, leaving a bounded set of possible keys that anyone with the disclosure and enough compute can reproduce offline, without ever touching a device. The sweeping has not stopped almost three days later, and the falling average haul says the profitable end of that key space is already picked over.
