tradingkey.logo

tradingkey.logo
怜玢


Another 486 wallets suffer losses in fourth wave of Coldcard wallet drain

CryptopolitanAug 3, 2026 11:36 AM
facebooktwitterlinkedin
すべおのコメントを芋る0


The Coldcard vulnerability has endured four waves of exploits so far, draining idle wallets. Long-term holders who did not move their coins are still vulnerable. 

The Coldcard exploiter has been active again, moving funds to a growing list of destination wallets. As Cryptopolitan reported, the initial attack against 500 wallets was not the only exploit, and losses quickly climbed to over $70M. 

As of August 3, holders of several versions of the Coinkite wallets are still at risk, and the only solution is to move their coins as soon as possible to new, safely derived wallets. 

Coldcard wallets appealed to Bitcoin maximalists and were widely recommended. Recently, white hat hackers have shown that even a few minutes of AI compute can discover vulnerable addresses. 

Before the fourth wave, the estimated losses affected 1,196 addresses for a total of 1,086.65 BTC, according to Galaxy Research data.

Coldcard’s fourth attack wave becomes more aggressive

On-chain researchers analyzing Coldcard addresses and BTC transactions have identified the pattern of a fourth wave of exploits. 

As of August 3, the attacker kept adding new destination wallets. After the wave was completed, the addresses sat idle for a few hours. 

According to Alex Thorn of Firmwide Research, the fourth wave most probably contains attempted attacks at multisig wallets, unlike the first three waves of transfers. An estimated 857 addresses were attacked, losing 486.11 BTC. The attacker launched multiple destination wallets, using new addresses to sweep Coldcard users, then consolidate the gains into larger wallets.

Losses are being reported by multiple influencers. The problem with Coldcard is that it has often been used for cold storage, and is not easily accessible to move the coins and update. Some Coldcard private keys were also stored on metal plaques, but this did not prevent the attacker from sweeping those wallets. 

The attacker apparently uses time-consuming computation, which exposes more batches of vulnerable wallets. This may delay the sweeping of new addresses, but the vulnerability still exists, and the fourth wave may not be the last. 

Coldcard undermines BTC anonymity and self-custody

For years, the BTC narrative was that self-custody was the ideal solution. Exchange hacks, frozen funds and lack of anonymity were the main arguments for taking coins off exchanges. 

BTC has been lost to compromised wallets before, but a mass vulnerability for a device is unprecedented. 

Further analysis of the Coldcard codebase showed the platform deliberately edited 2,500 lines of code with minimal comments, introducing weak entropy in wallet creation, noted Bitcoin maximalist @hodlonaut.

Reportedly, the more complex entropy function was disabled to make the code run without problems, thus potentially exposing thousands of wallets to being easily discovered. 

The Coldcard incident has also raised vigilance on potentially weak seeds, which can now be discovered with the help of rented computation. Trader Jameson Lopp recalled other widely used wallets reported flawed entropy bugs and patched them before the potential exploits. However, weakly derived addresses for cold storage remain a risk for new AI-powered attacks.

If you're reading this, you’re already ahead. Stay there with our newsletter.

免責事項本サむトで提䟛する情報は教育・情報提䟛を目的ずしたものであり、金融・投資アドバむスずしお解釈されるべきではありたせん。

コメント (0)

$ボタンをクリックし、シンボルを入力しお、株匏、ETF、たたはその他のティッカヌシンボルをリンクしたす。

0/500
コメントガむドラむン
読み蟌み䞭...

おすすめ蚘事

tradingkey.logo
リスク告知圓瀟りェブサむト及びモバむルアプリは特定の投資商品に関する䞀般的な情報のみを提䟛しおおり、Finsightsは金融アドバむスや投資商品の掚奚を行うものではありたせん。本情報の提䟛をもっおFinsightsが投資助蚀を行っおいるず解釈されるこずはありたせん。
投資商品には元本割れを含む重倧なリスクが䌎い、党おの投資家に適するものではありたせん。なお、過去の運甚実瞟は将来の成果を保蚌するものではありたせん。
Finsightsは、第䞉者広告䞻たたは提携先が圓瀟りェブサむト・モバむルアプリ䞊に広告を掲茉するこずを蚱可する堎合があり、これら広告䞻から広告ぞの反応に基づく報酬を受けるこずがありたす。
© 著䜜暩: FINSIGHTS MEDIA PTE. LTD. 無断耇写・転茉を犁じたす。