Odaily Planet Daily report: Alex Thorn, Head of Galaxy Research, posted on X that the attack targeting Coldcard wallets generated with weak random numbers is still ongoing. Users who still hold funds in affected single-signature Coldcard wallets should immediately migrate them to secure addresses. The team is continuously adding new victim and attacker addresses to its investigation database and plans to release updated statistics on the number of affected addresses via Galaxy Research.
It noted that the previously detected first, second, and third waves of attacks exhibited clear automated characteristics, and the stolen BTC remains in the attacker addresses without any transfer. However, recently, smaller-scale attackers have begun exploiting the vulnerability to steal funds and move them through chain stripping and cross-chain services. It is confirmed that all single-signature wallet addresses generated by Coldcard after the firmware upgrade in March 2021 are potentially at risk, and users should migrate their funds as soon as possible.
Previously, Galaxy Research disclosed that the Coldcard vulnerability exploit involved approximately 1,367.05 BTC (around $88.6 million) across about 4,585 addresses.

