Interestana
Home/News/Bitcoin Cold-Wallet Attack Hits 4,500 Addresses, Losses Near $89M
CoinDesk3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Bitcoin Cold-Wallet Attack Hits 4,500 Addresses, Losses Near $89M

Bitcoin Cold-Wallet Attack Hits 4,500 Addresses, Losses Near $89M

A significant and evolving Bitcoin cold-wallet attack has impacted an estimated 4,500 addresses, with cumulative losses approaching $89 million. The ongoing exploitation, first identified by blockchain analytics firm Galaxy Research, targets vulnerabilities in hardware wallets, specifically those generating keys using the Coldcard device. This sophisticated attack has progressed through multiple "waves," indicating a persistent and adaptive threat actor.

The initial phase of the attack focused on exploiting weak keys generated by Coldcard hardware wallets. These keys, intended to secure Bitcoin holdings offline, were compromised, allowing attackers to gain unauthorized access to user funds. Galaxy Research has been instrumental in tracking the progression of these attacks, noting a shift in the attacker's methodology. In the latest wave, the attacker has begun targeting smaller Bitcoin balances, a strategic change that could indicate an effort to maximize the number of compromised accounts or to evade detection by focusing on less conspicuous transactions.

Furthermore, the attacker has demonstrated an ability to alter how funds are collected on-chain. This suggests a complex operational security strategy, potentially involving multiple wallets and transaction obfuscation techniques to make tracing the stolen Bitcoin more difficult. The total value of Bitcoin stolen in this attack is substantial, with preliminary estimates placing the losses at approximately $89 million. The attack underscores the critical importance of robust key management practices and the need for continuous vigilance against emerging threats in the cryptocurrency space.

Galaxy Research's ongoing analysis highlights the dynamic nature of cryptocurrency exploits. The firm's flagging of the third wave of sweeps indicates that the threat is not static and that attackers are actively refining their methods. The targeting of Coldcard-generated keys specifically points to a potential vulnerability within the key generation process of this particular hardware wallet, or a widespread issue with how users are managing their seed phrases and private keys when interacting with the device. The increasing number of affected addresses, now at around 4,500, signifies the broad reach of this exploit. The cryptocurrency community and hardware wallet manufacturers are likely to be closely monitoring this situation for further developments and potential mitigation strategies.

Original source — read the full reporting at the publisher:

Read on CoinDesk

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next