BlocktoBlockto
Bitcoin Wallet Attack Expands to 4,500 Addresses as Losses Approach $89 Million
TECH

Photo: Illustrative

Bitcoin Wallet Attack Expands to 4,500 Addresses as Losses Approach $89 Million

Galaxy Research has identified a third wave of attacks tied to a Coldcard hardware wallet vulnerability, with roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning. Unlike the initial wave on July 30, which averaged nearly a full bitcoin per victim across 1,083 bitcoin taken from 1,196 addresses in just 41 minutes, this latest round shows the attacker now going after smaller wallets worth only a few thousand dollars each.

Laurisa
By Laurisa

Junior Author · August 2, 2026

2 min
Key takeaways
Galaxy Research has identified a third wave of attacks tied to a Coldcard hardware wallet vulnerability, with roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning.
Unlike the initial wave on July 30, which averaged nearly a full bitcoin per victim across 1,083 bitcoin taken from 1,196 addresses in just 41 minutes, this latest round shows the attacker now going after smaller wallets worth only a few thousand dollars each.
Total Losses Climb Across Three Waves Combined losses across all three waves have reached 1,367 bitcoin, close to $89 million , spread across 4,585 addresses.

Galaxy Research has identified a third wave of attacks tied to a Coldcard hardware wallet vulnerability, with roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning. Unlike the initial wave on July 30, which averaged nearly a full bitcoin per victim across 1,083 bitcoin taken from 1,196 addresses in just 41 minutes, this latest round shows the attacker now going after smaller wallets worth only a few thousand dollars each.

Total Losses Climb Across Three Waves

Combined losses across all three waves have reached 1,367 bitcoin, close to $89 million, spread across 4,585 addresses. The attacker behind wave three has changed tactics, sending stolen funds to individual destinations rather than shared collector addresses, making the theft harder to trace. Funds are also being routed into pay-to-witness-script-hash outputs, which can support multisignature or timelock conditions, instead of simpler single-key formats used earlier.

Vulnerability Traces Back to 2021 Firmware Flaw

The root cause remains a March 2021 firmware update that generated wallet seeds using predictable software-based randomness rather than the device’s hardware randomizer, leaving a limited set of possible keys that can be reconstructed offline by anyone with knowledge of the flaw. Galaxy Research says it cannot confirm whether the same operator is behind all three waves or if a second party is independently exploiting the same vulnerability, though each wave appears internally consistent with a single actor.

Attack Shows Signs of Slowing Returns

Nearly three days after the exploit began, sweeps are continuing, though the shrinking average payout per victim suggests the most valuable vulnerable wallets have already been drained.

How markets are positioning

Live market reaction

🛢️WTI Crude
+3.4%
Gold
+1.8%
Bitcoin
-1.8%
$DXY
+0.6%

Disclaimer

This content is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency trading involves risk and may result in financial loss.

Exclusive partner offer

Start trading
with BloFin today

Up to $500 sign-up bonus and zero-fee trading on your first 30 days.

Buy crypto now

You will be redirected to BloFin

Share article

About the author

Laurisa
Laurisa

Emerging voice in crypto journalism with a background in fintech and digital economics. Covers DeFi, NFTs, and the evolving regulatory landscape.