
Galaxy Research reported a third wave of on-chain “sweeps” linked to allegedly weak private keys generated by certain Coldcard hardware wallets. The attacker is now moving to smaller balances and has changed how funds are consolidated on-chain, according to the firm’s analysis.
Attacker Shifts to Smaller Balances
In this latest phase, addresses with lower holdings are being targeted, a departure from earlier activity tied to the same weakness. Galaxy Research also noted operational changes in how the stolen funds are gathered and moved on-chain, indicating an evolving strategy.
How Weak Keys Enable Sweeps
On-chain “sweeps” typically occur when an attacker reconstructs or predicts a wallet’s private key, enabling immediate control of funds. Weak or insufficiently random key generation can leave wallets vulnerable to such attacks. Galaxy Research’s findings attribute the current activity to a set of Coldcard-generated keys deemed weak, though the firm did not publish detailed technical specifics in its summary.
Why It Matters
- Key-generation vulnerabilities can compromise self-custodied funds regardless of balance size.
- Shifts in consolidation patterns suggest continued adaptation by the attacker, complicating detection and attribution.
- The incident underscores the importance of robust entropy in wallet creation and ongoing monitoring of on-chain anomalies.
Background
Galaxy Research is the research division of Galaxy Digital, a digital asset and blockchain-focused financial services firm. Coldcard is a popular Bitcoin hardware wallet produced by Coinkite. The report highlights continuing risks associated with weak key generation and the need for vigilance as attacker behavior evolves.