A wave of Bitcoin cold-wallet attacks has escalated dramatically, with the number of compromised addresses soaring to 4,500 and cumulative losses nearing $89 million. According to a new report from Galaxy Research, this marks a third wave of malicious sweeps targeting wallets that generated keys using Coldcard hardware, a popular choice among security-conscious users. The attacker has shifted tactics, now going after smaller balances and altering how stolen funds are collected onchain, raising fresh concerns about the safety of even the most "cold" storage solutions.

The Third Wave: A New Phase of the Attack

Galaxy Research's latest findings reveal that the attack is far from over. The third wave of sweeps represents an evolution in the attacker's methodology. Unlike earlier phases that focused on larger, high-value wallets, this new wave is sweeping funds from a much broader set of addresses, including those with relatively small balances. This suggests the attacker is casting a wider net, possibly to maximize total haul while reducing the risk of detection.

The shift in targeting is significant. Previously, the attacker may have prioritized wallets with substantial holdings, but now they are systematically draining any vulnerable address. This could indicate that the attacker has automated the process, or that they are exploiting a vulnerability that affects a wider range of Coldcard-generated keys than initially thought.

Changing Onchain Collection Tactics

One of the most notable changes is in how the stolen funds are collected. The attacker has altered their onchain behavior, possibly to obfuscate the flow of funds or to avoid exchange blacklists. This change makes it harder for investigators to trace the movement of the stolen Bitcoin, and it could complicate efforts to freeze or recover the assets.

What This Means for Coldcard Users

Coldcard has long been considered one of the most secure hardware wallets on the market, often recommended for those who prioritize self-custody and offline storage. However, this attack highlights a potential weakness in the key generation process. If the keys themselves are compromised, even a hardware wallet cannot protect against theft.

Users who have generated keys using Coldcard devices, especially those who did so during certain firmware versions or with specific configurations, should be on high alert. It is crucial to check whether any of their addresses have been affected. The fact that the attack is now targeting smaller balances means that even those with modest holdings are not safe.

Recommended Actions for Affected Users

  • Immediately transfer any remaining funds from potentially affected addresses to a newly generated wallet using a different device or a well-vetted software wallet.
  • Audit all addresses that were derived from Coldcard-generated seeds, even if they appear to be empty.
  • Stay updated with official communications from Coldcard and Galaxy Research for the latest guidance.
  • Consider using multi-signature setups to add an extra layer of security.

The Broader Implications for Bitcoin Security

This incident serves as a stark reminder that no single security measure is foolproof. Even the most reputable hardware wallets can be compromised if the underlying key generation process is flawed. The attack also underscores the importance of diversifying security practices and not putting all eggs in one basket.

For the broader Bitcoin community, this could prompt a reevaluation of best practices. It may lead to increased adoption of multi-sig wallets, which require multiple keys to authorize a transaction, making it significantly harder for an attacker to steal funds. Additionally, it highlights the need for ongoing research and vigilance in the face of evolving threats.

Key Takeaways

  • The Bitcoin cold-wallet attack has expanded to 4,500 addresses, with losses nearing $89 million.
  • The attacker has launched a third wave, now targeting smaller balances and changing onchain collection methods.
  • Coldcard users are urged to take immediate action to secure their funds.
  • This event highlights the importance of diversified security strategies, including multi-signature wallets.