What to Know

  • Three distinct waves of bitcoin sweeps have drained 1,367 bitcoin from 4,585 addresses.
  • The observed losses are worth nearly $89 million at recent prices.
  • The activity is tied to weak Coldcard-generated keys connected to a March 2021 firmware release.
  • The latest wave drained roughly 208 bitcoin from 1,912 addresses between Friday midday and Saturday morning UTC.
  • The July 30 opening wave took 1,083 bitcoin from 1,196 addresses in 41 minutes.
  • The newest wave is targeting smaller balances, averaging just over a tenth of a bitcoin per victim.
  • Market researchers believe each wave is internally the work of a single operator, but blockchain data does not prove whether the same attacker is behind all three waves.
  • The third wave changed its onchain collection style by sending each victim’s coins to its own destination and using pay-to-witness-script-hash outputs.

Cold Wallet Security Incident Deepens

A bitcoin cold-wallet security incident linked to weak Coldcard-generated keys has expanded across thousands of addresses, with observed losses now totaling 1,367 bitcoin from 4,585 addresses. At recent prices, the drained funds are valued at nearly $89 million, making the episode a major reminder that offline storage can still be exposed when key generation is flawed.

The sweeps are tied to a vulnerability in a March 2021 Coldcard firmware release. The flaw routed seed generation through a predictable software randomizer instead of the device’s hardware random source. That distinction is critical in bitcoin custody because seed generation is the foundation of wallet security. If the randomness behind a seed is weak or reproducible, attackers may be able to recreate the same private keys without physically accessing the hardware wallet.

In this case, the weakness left a bounded set of possible keys. Anyone with knowledge of the issue and enough computing power could attempt to reproduce those keys offline. That means the attacker would not need to touch a device, obtain a user’s seed phrase, or compromise an exchange account. The attack surface is the mathematical space created by predictable randomness.

Three Waves Have Now Hit Bitcoin Addresses

The activity has unfolded in three distinct waves. The opening wave on July 30 moved with striking speed, draining 1,083 bitcoin from 1,196 addresses in 41 minutes. That first stage averaged close to a full coin per affected address, suggesting that the attacker initially focused on richer targets within the vulnerable key space.

The latest wave is different. Early Sunday monitoring flagged a third wave that drained roughly 208 bitcoin from 1,912 addresses between Friday midday and Saturday morning UTC. That works out to just over a tenth of a bitcoin per victim, showing that the attacker is now sweeping smaller balances than those hit in the initial run.

The decline in the average haul matters. It suggests that the most profitable portion of the vulnerable key space may already have been picked over. When attackers move from larger balances to smaller ones, it often indicates that the low-hanging targets have been exhausted and that the remaining exposed addresses require more scanning effort for less reward.

Across all observed waves, the total now stands at 1,367 bitcoin from 4,585 addresses. The nearly $89 million figure highlights the scale of the problem, but the address count is equally important. This is not a single large wallet failure. It is a broad, systematic drain across many wallets whose keys appear to have been derived from the same weak generation process.

Latest Sweep Uses Harder-to-Trace Patterns

The third wave also changed how funds are collected onchain. In the first two waves, the attacker used a handful of shared collector addresses, which made the activity easier for blockchain analysts and market participants to map. In the newest wave, each victim’s coins are sent to its own destination, creating a more distributed footprint.

The funds are also being parked in pay-to-witness-script-hash outputs. This output type can support more complex spending conditions, including multisignature or timelock arrangements. Earlier sweeps used plain single-key outputs, which are simpler to interpret. The change does not prove a specific motive, but it does make the latest movement more complicated to follow at a glance.

The batching behavior changed as well. The latest wave batched an average of six victims into each sweep, while the first wave took exactly one victim at a time. This shift may reflect an attempt to improve operational efficiency, reduce visibility, or adapt after earlier activity was publicly mapped. Technical traders and blockchain watchers often pay close attention to these structural changes because they can reveal how an attacker is adjusting under scrutiny.

The third wave also scanned only the default derivation path, the standard branch of the wallet key tree checked first. Earlier activity tested several branches per seed. A default-path-only approach may be faster and narrower, but it can also leave some potential addresses untested if users used nonstandard paths. The tactical change is one reason analysts are cautious about linking all waves to one person or group.

Attribution Remains Limited by Blockchain Data

Market researchers are confident that each individual wave is internally consistent with one operator. However, they are not linking all three waves as the work of the same attacker. Public blockchain data can show transaction flows, output formats, timing, address clusters, and spending patterns, but it does not directly reveal who controls the keys or whether separate sweeps are coordinated.

That leaves two broad possibilities. The same operator may have rebuilt the strategy after earlier activity was identified publicly, changing collection methods and transaction structure to make the next wave harder to map. Alternatively, a different operator may be grinding through the same vulnerable key space independently, using similar knowledge but different techniques.

The blockchain does not settle that question. It can display the movement of coins, but it cannot identify whether the person or system behind each wave is the same. For victims, the distinction may not change the outcome. For investigators and wallet users, however, attribution matters because multiple independent operators would imply that the vulnerable key space remains attractive to more than one attacker.

Why Weak Randomness Is So Dangerous for Bitcoin

Bitcoin ownership depends on private keys. A wallet seed is used to derive those keys, and strong randomness is what makes the seed effectively impossible to guess. Hardware wallets are designed to protect that process by generating secrets in an isolated environment, ideally using a robust hardware random source.

When randomness becomes predictable, the security model changes completely. Instead of trying to steal a seed phrase from a user, an attacker can search through the reduced set of possible seeds. If the search space is bounded enough, and if the attacker has sufficient compute resources, wallets generated under the flawed process can be discovered and emptied.

This type of incident is especially troubling because affected users may have believed their funds were in cold storage and therefore out of reach. Cold storage reduces exposure to online malware, phishing, exchange insolvency, and remote account takeover. But it does not fix a flawed seed. If the seed itself was generated from weak entropy, the wallet may be vulnerable even if the device never connects to a compromised computer.

The Coldcard issue tied to the March 2021 firmware release illustrates that custody risk is not limited to user behavior. It can also arise from implementation details deep inside wallet firmware. For the broader bitcoin market, the episode reinforces the importance of firmware review, reproducible builds, disclosure processes, and user migration guidance when flaws are found.

Smaller Balances Now in the Crosshairs

The newest sweep’s smaller average victim balance may be one of the most important developments for everyday holders. The opening wave averaged close to a full coin, while the latest wave averaged just over a tenth of a bitcoin per victim. That shift indicates that exposure is not limited to larger wallets.

For attackers, a large number of smaller wallets can still be worthwhile if the key search process is automated. Once vulnerable keys can be reproduced offline, the marginal cost of scanning and sweeping additional addresses may be relatively low. The third wave’s broader address count, with 1,912 addresses affected in the latest drain, shows how quickly smaller balances can add up.

For users, the lesson is uncomfortable but clear. The size of a wallet balance is not a security control. If a key is weak, even a modest holding can be swept. The fact that the profitable end of the key space appears to be picked over does not mean the threat has ended. It may simply mean that the attacker is moving down the value curve.

What Bitcoin Holders Should Take From the Incident

FXCOINZ market coverage views this incident as a custody warning rather than a bitcoin protocol failure. The bitcoin network is operating as designed: valid signatures move coins. The weakness appears to be in the process by which certain wallet keys were generated, not in the underlying consensus system.

That distinction matters for investors. Bitcoin’s base-layer cryptography remains separate from the operational practices of wallet manufacturers and users. However, holders who used affected firmware or generated seeds during vulnerable conditions may face risk that cannot be solved by simply waiting. If an attacker can reproduce a private key, the race becomes about who moves the funds first.

General best practice in such situations is to move funds to a newly generated wallet that uses strong randomness and current, trusted software. Users should avoid reusing old seeds if those seeds may have been generated under flawed conditions. They should also understand that updating firmware does not necessarily repair a seed already created with weak randomness. A new secure seed is required if the old one is suspect.

The incident also highlights the importance of monitoring public disclosures and wallet security advisories. Hardware wallets are powerful tools, but they are not magic boxes. Their security depends on proper design, secure firmware, transparent response to flaws, and users following migration instructions when vulnerabilities are identified.

Market Impact and Broader Crypto Security Implications

The immediate market impact is primarily reputational and operational rather than a direct change to bitcoin’s supply dynamics. The drained coins were already in circulation, and the attack does not create new bitcoin or alter the network’s monetary policy. Still, custody incidents can affect market sentiment, especially when they involve cold storage products that users rely on for long-term holding.

Security failures also shape how institutions and sophisticated investors evaluate self-custody. Many crypto participants prefer hardware wallets because they reduce dependence on custodians. At the same time, institutional users often require layered controls, including multisignature arrangements, independent key generation processes, and operational checks designed to avoid single-device failure.

The attacker’s use of pay-to-witness-script-hash outputs in the latest wave may draw additional attention from onchain analysts because the format can support more complex scripts. While that does not by itself reveal where the coins will go next, it adds another layer of complexity to tracking the proceeds. The shift from shared collector addresses to unique destinations for each victim also reduces the simplicity of earlier mapping efforts.

As long as sweeps continue, the vulnerable key space remains a live concern. The fact that activity has persisted almost three days later shows that the search is not merely historical. The falling average haul suggests diminishing returns, but not necessarily an end to the operation. For bitcoin holders, the practical takeaway is that secure key generation is not optional; it is the foundation of ownership.

Frequently Asked Questions (FAQs)

Three waves of bitcoin sweeps have drained funds from addresses tied to weak Coldcard-generated keys. The activity has taken 1,367 bitcoin from 4,585 addresses, with losses valued at nearly $89 million at recent prices.

What caused the wallet vulnerability?

The flaw traces to a March 2021 Coldcard firmware build that routed seed generation to a predictable software randomizer instead of the chip’s hardware random source. That created a bounded set of possible keys that could be reproduced offline.

How much bitcoin was taken in the latest wave?

The latest wave drained roughly 208 bitcoin from 1,912 addresses between Friday midday and Saturday morning UTC. The average amount taken was just over a tenth of a bitcoin per victim.

How did the first wave compare with the latest one?

The July 30 opening wave drained 1,083 bitcoin from 1,196 addresses in 41 minutes and averaged close to a full coin per affected address. The latest wave targeted smaller balances across a larger number of addresses.

Is the same attacker behind all three waves?

Market researchers believe each wave is internally consistent with one operator, but they are not linking all three waves to the same attacker. Public blockchain data does not prove whether the waves are coordinated or independent.

Why is weak randomness dangerous for bitcoin wallets?

Weak randomness can make wallet seeds predictable. If attackers can reproduce a seed, they can derive the associated private keys and move the bitcoin without accessing the physical hardware wallet.

Did the bitcoin network itself fail?

No. The issue is tied to wallet key generation, not the bitcoin protocol. The network processes valid transactions, and the vulnerability appears to involve how certain wallet seeds were created.

Why are the latest transactions harder to trace?

The third wave sends each victim’s coins to its own destination instead of a handful of shared collector addresses. It also uses pay-to-witness-script-hash outputs, which can carry more complex spending conditions.

What should affected users understand?

Users who generated seeds under vulnerable conditions should understand that updating firmware may not fix an already weak seed. Funds at risk generally need to be moved to a newly generated wallet using strong randomness and current trusted software.

Photo by Alesia Kozik on Pexels