Loading...

Bitcoin Cold Wallet Exploit Spreads to Over 4,500 Addresses as Losses Climb to ~$90 Million

August 13, 2026
21 hours ago
News
0 Likes
3 Views
Bitcoin Cold Wallet Exploit Spreads to Over 4,500 Addresses as Losses Climb to ~$90 Million

A major Bitcoin cold wallet exploit has now spread to more than 4,500 wallet addresses, with total losses climbing to approximately $90 million (1,367 BTC). Researchers say the attack is linked to vulnerable Coldcard wallet firmware that generated predictable wallet seeds, allowing attackers to reconstruct private keys and drain funds without ever accessing the physical devices.


According to Galaxy Research, the exploit has now affected 4,585 Bitcoin addresses across three coordinated attack waves, making it one of the largest self-custody wallet compromises ever recorded. The latest wave pushed total stolen funds to 1,367 BTC, up from approximately 1,083 BTC reported a day earlier.


The attack was first identified on July 30, when hackers drained about 594 BTC from nearly 500 wallets. A second, much larger wave later impacted more than 1,196 wallets, significantly increasing the scale of the incident.

Researchers say the vulnerability does not stem from hackers breaking into Coldcard hardware wallets. Instead, it originated from a firmware build configuration that caused affected devices to generate wallet seeds using predictable hardware values instead of a secure hardware random-number generator. Since every Bitcoin private key is derived from its wallet seed, attackers who successfully recreated those weak seeds were able to generate the corresponding private keys and transfer users' funds without needing physical access to the wallets.


The third wave also shows attackers refining their tactics. Instead of consolidating stolen Bitcoin into a few collection wallets as seen previously, the latest operation distributes funds across separate destination addresses using Pay-to-Witness-Script-Hash (P2WSH) outputs, making blockchain tracking more difficult.


The incident also exposes an important supply-chain risk within hardware wallet security. Even users who securely stored their wallets offline for years remained vulnerable if their wallets were originally created using the affected firmware, regardless of whether the device was updated later. The attack highlights that hardware wallet security depends not only on offline storage but also on the integrity of wallet generation. With Galaxy Research warning that attackers are still


Tags: News Featured

Stay Informed

Get the latest crypto insights delivered to your inbox weekly.