Bullish

Coldcard Exploit Hits 4,585 Addresses With $89M Losses

2026-08-02 09:13:52

Three waves of Coldcard key exploits compromise 4,585 addresses, draining $88.6M in BTC. Funds remain unspent across monitored addresses, highlighting persistent firmware risks.

Woofun AI reports that three distinct attack waves exploiting Coldcard key vulnerabilities have impacted 4,585 addresses, resulting in total losses of approximately $88.6 million in BTC. The first two waves shared similar patterns, including concentrated fund transfers to shared addresses and identical P2WPKH output formats, occurring 27 hours apart. The third wave diverged significantly by utilizing separate destination addresses for each victim, storing funds in P2WSH addresses, and processing an average of 6.37 victims per transaction batch.

The attacker currently controls 1,366.3865 BTC, with none of the funds in terminal addresses having been spent. The 1,158.8148 BTC from the initial waves are distributed across seven monitored addresses. All stolen BTC originated from blocks mined after the vulnerable firmware release on March 17, 2021. While on-chain data confirms each wave was executed by a single actor, it cannot verify if all three waves share a common perpetrator.

WOOFUN AI

Impact Assessment · Quick Read

The scale of this exploit, involving nearly $90M in BTC, underscores the critical security risks associated with legacy hardware wallet firmware. The fact that funds remain unspent suggests the attacker may be waiting for optimal laundering conditions or market timing. This incident reinforces the need for rigorous key management audits and highlights potential systemic vulnerabilities in older cryptographic implementations.
Generated by WOOFUN AI · For reference only, not investment advice

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions