Bitcoin Cold-Wallet Attack Hits 4,500 Addresses, $89M Losses

Galaxy Research reported a third wave of on-chain “sweeps” linked to allegedly weak private keys generated by certain Coldcard hardware wallets. The attacker is now moving to smaller balances and has changed how funds are consolidated on-chain, according to the firm’s analysis.

Attacker Shifts to Smaller Balances

In this latest phase, addresses with lower holdings are being targeted, a departure from earlier activity tied to the same weakness. Galaxy Research also noted operational changes in how the stolen funds are gathered and moved on-chain, indicating an evolving strategy.

How Weak Keys Enable Sweeps

On-chain “sweeps” typically occur when an attacker reconstructs or predicts a wallet’s private key, enabling immediate control of funds. Weak or insufficiently random key generation can leave wallets vulnerable to such attacks. Galaxy Research’s findings attribute the current activity to a set of Coldcard-generated keys deemed weak, though the firm did not publish detailed technical specifics in its summary.

Why It Matters

  • Key-generation vulnerabilities can compromise self-custodied funds regardless of balance size.
  • Shifts in consolidation patterns suggest continued adaptation by the attacker, complicating detection and attribution.
  • The incident underscores the importance of robust entropy in wallet creation and ongoing monitoring of on-chain anomalies.

Background

Galaxy Research is the research division of Galaxy Digital, a digital asset and blockchain-focused financial services firm. Coldcard is a popular Bitcoin hardware wallet produced by Coinkite. The report highlights continuing risks associated with weak key generation and the need for vigilance as attacker behavior evolves.

×