Coldcard Drain Reaches 1,367 BTC As Galaxy Finds Third Suspected Wave
0
0

Galaxy Research identified a third suspected attack wave involving Bitcoin addresses believed to have been generated by vulnerable Coldcard firmware.
The latest wave drained 207.7294 BTC, lifting the estimated observed total to 1,367.05 BTC across 4,585 addresses. Galaxy valued the combined transfers at approximately $88.6 million when it published the update.
Third Wave Uses Different Transaction Pattern
The first two suspected waves followed similar onchain patterns, including a funnel structure that moved funds into a small group of shared collector addresses and used pay-to-witness-public-key-hash destinations.
The third wave used pay-to-witness-script-hash destinations and batched an average of 6.37 victim addresses into each transaction. The differences could reflect the same attacker changing tools or a separate operator exploiting the same address-generation weakness.
Galaxy has not independently verified that every affected address was created through Coldcard’s weak random-number process. Its findings remain an onchain estimate rather than definitive proof that all three waves came from one attacker or one vulnerable device group.
The latest total surpasses the earlier estimate of up to 1,083 BTC traced after Block and Coinkite first disclosed the seed-generation vulnerability.
Coinkite Broadens Affected Device List
Coinkite’s updated security advisory now covers Mk2 and Mk3 seeds generated on firmware 4.0.1 through 4.1.9, along with Mk4 and Mk5 seeds created before standard firmware 5.6.0 or Edge 6.6.0X.
Coldcard Q seeds generated before standard version 1.5.0Q or Edge version 6.6.0QX are also affected. Coinkite estimates that vulnerable Mk4, Mk5 and Q seeds contained about 72 bits of entropy instead of the intended 128 bits.
Fixed firmware is available for each affected model, but installing an update does not repair a seed created under vulnerable firmware. Moving the same recovery phrase into another wallet also leaves the funds exposed.
Seeds supplemented with at least 50 fair, independent and private dice rolls are not considered vulnerable through this randomness flaw alone. A strong, unique BIP-39 passphrase adds another barrier, although Coinkite still recommends migrating the funds.
Block Traces RNG Error To March 2021
Block’s technical investigation traced the weakness to a March 2021 firmware change that caused Coldcard’s random-number library to use a deterministic MicroPython fallback instead of the device’s STM32 hardware generator.
Mk2 and Mk3 version 4 firmware added no cryptographic entropy to that fallback. Newer devices introduced secure-element input but retained only four bytes during reseeding, limiting the securely distinguished output streams to no more than 2^32 under fixed fallback conditions.
The disclosure follows ZachXBT’s earlier claim that hardware wallets were “garbage” and his recommendation to use a dedicated iPhone for crypto storage. His comments focused on broader wallet software and operational risks and did not identify the Coldcard entropy defect.
Affected users should install the fixed firmware before generating a replacement seed, verify the new backup and receive address, send a small test transaction and move the remaining balance only after confirming that the test funds arrived.
The post Coldcard Drain Reaches 1,367 BTC As Galaxy Finds Third Suspected Wave appeared first on Crypto Adventure.
0
0
Verbind de portfolio die je gebruikt veilig om te beginnen.





