Coldcard wallet users may be facing a fourth organized wave of attacks, potentially bringing total losses linked to the vulnerability to 2,055 BTC, worth about $130mn, according to Galaxy Research.
Coldcard Losses Reach $130mn as Fourth Wave of Attacks Begins
Alex Thorn, Galaxy's head of research, said in a 4 Aug X post that an estimated 15 attackers were now exploiting the vulnerability. Users have been advised to transfer any remaining crypto held on affected devices to alternative wallets.
Waves of attack
Coinkite, the Canadian manufacturer behind Coldcard, published on 30 Jul a security warning about a vulnerability in its Mk3 device affecting recovery phrases dating back to March 2021.
The vulnerability caused wallets to stop using a dedicated chip to generate the randomness required for seed phrases, instead relying on a software-based formula. An attacker who determined that formula could reconstruct the seed phrases and gain access to the wallets.
Coinkite estimated that the vulnerability left Mk3 devices generating seed phrases with about 40 bits of randomness, while Mk4, Mk5 and Q devices produced about 72 bits, well below the 128 bits expected from a standard 12-word phrase. That reduced the task of reconstructing a seed phrase from effectively impossible to something a computer could complete within hours.
The company released an emergency update meant to protect remaining wallets, however users also had to generate a new recovery phrase after the update, leaving many vulnerable.
Galaxy recorded 1,083 BTC drained from 1,196 addresses in the first hour of the attack, worth $70.2mn and averaging close to a whole Bitcoin per victim. A second wave 27 hours later took 76.2 BTC from 1,478 addresses, and a third, flagged on 2 Aug, took an estimated 208 BTC from 1,912 addresses. Average losses per victim fell with each wave, down to about 0.1 BTC by the third, as attackers worked through progressively smaller wallets.
Thorn flagged the suspected fourth wave on 3 Aug while it was still underway, initially identifying 389 BTC transferred from 462 victim addresses to 216 newly created destinations. Galaxy later raised its estimate to about 449 BTC and said it had medium-high confidence that most of the activity was carried out by a single operator. The firm described the sweeps as automated and programmatic, potentially with assistance from AI models.
Coinkite apologizes
Coinkite founder Rodolfo Novak issued a public apology on X shortly after the first exploit, stating that the company was "heartbroken" and taking "full accountability for the firmware bug." He added that Coinkite is "committed to working with affected users who want to pursue a police report, insurance claim, or their own investigation."
The statement did not address whether Coinkite will compensate users whose coins are already gone, the question dominating replies to the post. The company has also drawn criticism online for retaining customer email records, which critics argue gave attackers a ready-made list of potential wallets.
Galaxy stated in an X post that 90% of the stolen coins have not moved, remaining in the attacker addresses the firm initially identified. The company is working directly with 73 victims and passing confirmed addresses to US federal law enforcement, exchanges and cyber investigation groups.