Galaxy Research has identified a third wave of fund sweeps linked to compromised Coldcard-generated keys. The perpetrator is now shifting focus toward smaller balances and employing more sophisticated on-chain collection methods.
- A vulnerability within the March 2021 Coldcard firmware has allowed attackers to systematically strip bitcoin from thousands of wallets by recreating keys produced via weak software-based randomness.
- Across three distinct attack waves, approximately 1,367 bitcoin—valued at nearly $89 million at current market rates—has been stolen from 4,585 addresses. The most recent wave targets smaller amounts using complex transaction patterns that are harder to track.
- While Galaxy Research suspects each individual wave is managed by a single operator, they cannot confirm if a single attacker is responsible for all three, as the blockchain lacks data to link separate sweeps.
The attacker exploiting Coldcard-generated keys is currently draining wallets containing only a few thousand dollars each.
Galaxy Research reported a third wave of sweeps early Sunday, with roughly 208 bitcoin taken from 1,912 addresses between Friday midday and Saturday morning UTC. This averages out to just over 0.1 BTC per victim. In contrast, the initial wave on July 30 averaged nearly a full bitcoin, draining 1,083 BTC from 1,196 addresses in just 41 minutes.
Total losses across all three waves have reached 1,367 bitcoin (nearly $89 million) across 4,585 addresses.
In this third wave, coins are sent to unique destinations rather than the limited set of collector addresses used in previous waves, which had made them easy to map. Furthermore, the attacker is utilizing pay-to-witness-script-hash outputs—a format capable of supporting timelocks or multisignature conditions—instead of the standard single-key outputs used previously.
The attacker is now batching an average of six victims per sweep, whereas wave one targeted victims one by one. Additionally, the process is only scanning the default derivation path—the standard branch checked first by a wallet—rather than testing multiple branches per seed.
It remains unclear if this is the same operator returning after being identified by the public or a different attacker independently grinding the same vulnerable key space; the blockchain cannot distinguish between the two.
Galaxy Research noted they are certain each wave is run by a single operator but will not definitively link the three waves together.
The root cause is a March 2021 firmware update that directed seed generation to a predictable software randomizer instead of the hardware’s internal randomizer. This created a limited set of possible keys that can be reproduced offline by anyone with sufficient computing power, without needing physical access to a device.
Despite the discovery, the sweeping continues three days later, though the decreasing average amount suggests the most profitable part of that key space has already been exploited.



Binance continues to lead the crypto exchange market, growing from spot and derivatives into yield, savings, payments, RWAs, and broader financial services.
Why it matters:
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.


