Bitcoin Cold Wallet Attack Hits 4,500 Wallets, Losses Near $89 Million

The ongoing Bitcoin Cold Wallet Attack has escalated significantly, with blockchain researchers reporting that more than 4,500 Bitcoin wallet addresses have now been compromised. According to recent findings, the total amount stolen has climbed to nearly $89 million, making it one of the largest wallet security incidents of 2026.

Security experts believe the attackers are exploiting a vulnerability found in older Coldcard firmware that generated wallet seeds using weak software-based randomness instead of secure hardware-generated entropy.

Third Wave of Bitcoin Wallet Sweeps Detected

Researchers at Galaxy Research identified a third wave of attacks, revealing that hackers continue to drain Bitcoin from vulnerable wallets.

Unlike the first two waves, the latest operation focuses on wallets holding relatively smaller balances. During this phase, attackers reportedly stole around 208 BTC from 1,912 wallet addresses between Friday and Saturday (UTC).

This suggests that the hackers are now targeting wallets that were previously overlooked after emptying larger holdings during the initial attacks.

Total Losses Reach Nearly $89 Million

Across all three attack waves, blockchain analysts estimate that attackers have stolen approximately:

  • 1,367 BTC
  • 4,585 compromised wallet addresses
  • Estimated value: Nearly $89 million

The first attack wave was especially aggressive, draining more than 1,000 BTC from over 1,100 wallets within less than an hour.

Since then, attackers have continued scanning vulnerable addresses, steadily increasing the overall losses.

Attack Strategy Has Changed

Blockchain investigators observed several important changes in the third wave of the Bitcoin Cold Wallet Attack.

Instead of sending all stolen Bitcoin to a few common collection addresses, attackers now:

  • Transfer each victim’s funds to separate destination wallets.
  • Use more advanced Bitcoin transaction structures.
  • Combine multiple victims into a single transaction.
  • Focus only on the default wallet derivation path to speed up scanning.

These changes make it more difficult for analysts to track stolen funds compared to earlier attack waves.

What Caused the Vulnerability?

According to researchers, the exploit traces back to a March 2021 Coldcard firmware release.

The affected firmware accidentally relied on predictable software-generated randomness while creating wallet seed phrases instead of using the device’s dedicated hardware random number generator.

As a result, attackers can reproduce a limited range of possible private keys offline without ever accessing the physical hardware wallet itself.

This means the hardware device itself is not being hacked. Instead, wallets created using the vulnerable firmware may generate predictable recovery seeds that attackers can calculate.

Smaller Wallets Now Being Targeted

Researchers noted that the average amount stolen per wallet has declined significantly.

While the first attack wave primarily emptied high-value wallets, the latest campaign is targeting addresses holding only a few thousand dollars worth of Bitcoin.

This indicates that attackers are continuing to search through the remaining vulnerable key space after already compromising many larger balances.

How Bitcoin Users Can Stay Safe

If you generated a Bitcoin wallet using older Coldcard firmware, security experts recommend reviewing your wallet setup immediately.

Users should consider:

  • Updating to the latest firmware version.
  • Moving Bitcoin to a newly generated wallet created with updated firmware.
  • Verifying seed generation methods.
  • Keeping firmware updated from official sources only.
  • Never sharing or exposing recovery seed phrases.

The Bitcoin Cold Wallet Attack continues to evolve, with attackers adapting their methods while expanding the number of compromised wallets. With losses approaching $89 million and more than 4,500 addresses affected, the incident highlights how even historical software vulnerabilities can create long-term security risks for cryptocurrency holders.

Leave a Comment