Your Coldcard never touched the internet. No malware infected your laptop. Nobody laid a finger on the device. And yet, across three coordinated sweeps starting July 30, attackers have reportedly drained roughly 1,367 BTC — approximately $89 million — from more than 4,500 password vaults. The campaign, according to Galaxy Research, is still active.
The promise of cold storage just got a brutal stress test. Cold storage lost.
A Flaw Baked In Since 2021
A predictable randomizer replaced the hardware entropy source, making private keys reproducible offline.
The root cause traces back to a March 2021 Coldcard firmware update that, according to researchers, routed seed generation through a predictable software randomizer instead of the device’s hardware random number generator — the component specifically designed to make keys unreproducible. Think of it like a combination lock where every possible combination follows a discoverable pattern. The vault looks impenetrable. The math says otherwise.
Here’s what that flaw enabled:
- The March 2021 firmware made seed entropy — the randomness protecting your keys — reproducible by anyone with enough compute and the vulnerability details.
- No malware or physical access to the wallet was required. Readers alarmed by such computer problems may want actionable remediation steps.
- Wave 1 moved fast: approximately 1,083 BTC swept from 1,196 addresses in just 41 minutes.
- By wave 3, the average loss dropped to just over 0.1 BTC per victim — the highest-value wallets were already gone.
- Roughly 600 suspected attacker addresses have been handed to federal investigators.
The vulnerability existed for years before anyone exploited it. Some victims may have held funds since 2021, trusting hardware that was quietly compromised at the very moment of key creation.
The Sweep Is Still Running
Wave three broke the pattern attackers had established in the first two sweeps, complicating chain analysis and raising questions about who’s behind the operation.
Alex Thorn, Galaxy Research’s head of research, warned that an active sweep attack was underway against vulnerable single-signature Coldcard addresses created after the March 2021 update, urging users to move funds immediately.
Wave three showed a clear tactical shift. Instead of pooling stolen coins into shared collector addresses as in earlier waves, each victim’s funds went to separate P2WSH (pay-to-witness-script-hash) outputs — a move that makes blockchain tracing significantly harder.
Galaxy Research said it will not formally link the three waves, even though each appears internally consistent. The chain data alone cannot distinguish between one operator adapting and a second actor independently exploiting the same vulnerable key space — much like confidential files exposed through trusted ecosystems reveal systemic failures that go undetected for years.
The declining haul per wave suggests the most valuable targets are already empty. But if the vulnerable key space isn’t exhausted, more sweeps could follow. If your Coldcard wallet was created after March 2021 as a single-signature setup, treat it as compromised until proven otherwise.





























