Coldcard Theft Losses Near $114M as Fourth Attack Wave Hits

iconNS3
Share
AI summary iconSummary
Coldcard theft losses near $114M as a fourth attack wave hits, with altcoins to watch amid rising fear and greed index volatility. Galaxy’s Alex Thorn reported 448.7 BTC swept from 709 addresses. Coinkite issued emergency firmware and urged users to move funds to new seeds. Block’s security teams traced the flaw to a 2021 commit using MicroPython’s Yasmarang randomizer. Coinkite CEO Rodolfo Novak warned users to act fast if they generated a seed with a Coldcard.

Key Point

Attackers began a fourth wave of sweeps against bitcoin held in Coldcard hardware wallets, bringing estimated losses to roughly $114 million since Thursday. Alex Thorn, head of firmwide research at Galaxy, counted 448.7 BTC swept from 709 potential victim addresses in the latest wave. Coinkite released emergency firmware for every affected model, halted shipments, and told users to move funds to freshly generated seeds. Block's Bitcoin Engineering and Security teams traced the root cause to a March 1, 2021 commit that routed seed generation to MicroPython's Yasmarang software randomizer. Coinkite CEO Rodolfo Novak said users who generated a seed using a Coldcard wallet should move funds now.

Why it matters: A wallet-seed flaw can directly weaken self-custody confidence and may force rapid fund migration when users believe keys can be guessed.

Market Sentiment

Bearish, Stress-on, Event-driven, De-risking.

Reason: Estimated Coldcard-related losses reached roughly $114 million since Thursday, which points to direct custody stress for affected bitcoin holders.

Similar Past Cases

The Atomic Wallet compromise in June 2023 led users to report more than $35 million stolen, and Atomic Wallet later said less than 1% of monthly active users were affected. (Cointelegraph) The difference is that the Coldcard event centers on hardware-wallet seed generation, while Atomic Wallet involved a software wallet.

Ripple Effect

Weak seed generation can turn custody risk into urgent migration risk if users believe attackers can reproduce private keys. If replaceable transactions keep appearing in the mempool, then fee-bidding behavior can show whether victims are racing attackers or the wave is contained. Hardware-wallet makers may face higher scrutiny over firmware review and entropy design.

Opportunities & Risks

Opportunities: If emergency firmware and freshly generated seeds stop further sweeps, then restored custody confidence can become a stabilization signal for affected Bitcoin self-custody users.

Risks: If replaceable sweep transactions continue to appear in the mempool, then moving vulnerable funds to freshly generated seeds remains the key risk-reduction signal.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.