Bitcoin Cold-Wallet Attack Drains $89M Across 4,500 Addresses

A wallet-sweeping campaign exploiting Coldcard-generated keys has entered a third wave, according to analytics firm Galaxy Research. The attacker is emptying digital assets worth a few thousand dollars per target, bringing total observed losses across all three waves to 1,367 bitcoin, or nearly $89 million, from 4,585 addresses.

Wave Three Tactics and Blockchain Data

Galaxy Research flagged the latest surge early Sunday, documenting approximately 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC. This latest activity represents an average loss of just over a tenth of a bitcoin per victim, a departure from the opening wave on July 30. That initial assault averaged close to a full coin per target, draining 1,083 bitcoin from 1,196 addresses in just 41 minutes, according to blockchain records.

The attacker altered operational mechanics for the third wave. Instead of funneling stolen funds into a handful of shared collector addresses that made previous waves easy to map, wave three routes each victim’s coins to a unique destination. Furthermore, the attacker parks the assets in pay-to-witness-script-hash (P2WSH) outputs—a format capable of carrying multisignature or timelock conditions—rather than the plain single-key outputs utilized during the initial attacks.

Operational Changes in Key Scanning

Efficiency also marked the transition between the attacks. The campaign batched an average of six victims into each sweep during the third wave, contrasting with wave one, which targeted exactly one address at a time. The perpetrator also narrowed the scope of the sweep by scanning exclusively along the default derivation path—the standard branch of the key tree that a wallet checks first—rather than testing multiple branches per seed phrase.

Pro Tip: Hardware wallet users should remain vigilant about firmware updates, secure seed phrase generation environments, and monitoring derivation paths associated with their digital assets. Always verify transaction details on your physical device screen before signing.

Tracking the Escalation Across Campaign Waves

Comparing the three distinct waves highlights the attacker’s evolving strategy on the public ledger. While the first wave prioritized high-value targets in a rapid, single-address format, subsequent operations scaled down the individual payout size while increasing total target volume and obfuscating the final destinations through P2WSH outputs.

Campaign Wave Bitcoin Drained Addresses Targeted Average Per Victim
Wave One (July 30) 1,083 BTC 1,196 ~1.0 BTC
Wave Three (Recent) 208 BTC 1,912 ~0.1 BTC

Did you know? Pay-to-witness-script-hash (P2WSH) outputs allow Bitcoin users to lock funds with complex spending conditions, such as multiple required signatures or time delays before the coins can be spent.

Frequently Asked Questions

What caused the Coldcard-related wallet sweeps?

Analytics from Galaxy Research indicate an ongoing attacker is systematically draining funds from addresses utilizing keys generated via Coldcard workflows, accumulating nearly $89 million in total losses across three distinct waves.

HARDWARE WALLET HACK! 🚨 COLDCARD Users LOSE HUNDREDS OF BITCOIN! 🤯

How much bitcoin was stolen in the third wave?

The third wave resulted in the theft of approximately 208 bitcoin taken from 1,912 addresses between Friday midday and Saturday morning UTC, averaging just over a tenth of a bitcoin per victim.

How did the attacker change techniques in wave three?

The perpetrator routed each victim’s coins to separate destination addresses using pay-to-witness-script-hash (P2WSH) outputs, batched an average of six victims per sweep, and scanned only the default derivation path.

Stay Informed on Crypto Security

Explore our latest investigations and security analysis updates to stay ahead of emerging blockchain threats. Have questions or insights about these recent wallet sweeps? Leave a comment below or subscribe to our newsletter for direct updates.

Leave a Comment