Bitcoin Cold-Wallet Exploit Spreads to 4,500 Addresses
A new wave of sweeps linked to weak Coldcard-generated keys has expanded the Bitcoin cold-wallet exploit to roughly 4,500 addresses, with losses approaching $89 million. Galaxy Research says the attacker is now focusing on smaller balances and adjusting onchain collection methods, signaling a more adaptive campaign.
Key Takeaways
- A cold-wallet security incident tied to weakly generated Coldcard keys has now affected about 4,500 Bitcoin addresses.
- Total losses are approaching $89 million as the attacker continues a third wave of sweeps.
- The threat actor appears to be changing tactics, now targeting smaller balances and modifying how stolen funds are aggregated onchain.
- The incident underscores a critical lesson for self-custody users: secure key generation is just as important as offline storage.
Market Analysis
A fast-moving Bitcoin security incident is widening, with Galaxy Research reporting a third wave of wallet sweeps linked to weak Coldcard-generated keys. What began as a concentrated series of thefts has now expanded to roughly 4,500 addresses, pushing estimated losses close to $89 million.
The latest phase of the attack suggests the actor is not simply draining high-value wallets and disappearing. Instead, the pattern indicates a more patient and adaptive strategy. According to the research note, the attacker is now pursuing smaller balances and changing the way funds are collected onchain, likely to improve operational efficiency and reduce obvious clustering signals.
That shift matters for two reasons. First, it shows the campaign is still active and evolving rather than contained. Second, it suggests that even modest-sized wallets can remain exposed once a key-generation flaw becomes public and exploitable. In practical terms, the attack is no longer only a headline risk for large holders; it has become a broad self-custody risk for ordinary Bitcoin users.
For the broader market, the direct price impact of this kind of event is usually limited unless there is evidence of systemic wallet compromise or exchange exposure. However, security incidents of this scale can still shape sentiment around self-custody, hardware wallet trust, and operational security practices. Investors may become more cautious about cold-storage solutions if they believe the vulnerability was rooted not in user behavior, but in the wallet generation process itself.
The episode also highlights a recurring reality in crypto: storage is only as secure as the weakest step in the key lifecycle. Even a wallet marketed for offline protection can become dangerous if entropy, setup, or implementation is flawed. That makes audits, firmware transparency, and reproducible security practices increasingly important for hardware wallet vendors.
What's Next
The next phase will likely focus on attribution, wallet clustering, and whether additional affected addresses can be identified before more funds are moved. If the attacker continues sweeping smaller balances, the total damage could rise further even if the pace of individual thefts slows.
For users, the immediate takeaway is straightforward: verify the provenance of any cold-storage setup, move funds from compromised or suspect wallets, and avoid reusing potentially exposed key material. For the industry, the incident is another reminder that hardware security must be matched by rigorous randomness and secure implementation.
If confirmed, this could become one of the more consequential Bitcoin self-custody failures of the year—not because it threatens the network itself, but because it exposes how fragile wallet security can be when key generation goes wrong.