The exploitation of Coldcard hardware wallets has intensified dramatically, with new research indicating the campaign has compromised approximately 4,500 addresses and pushed cumulative losses toward $89 million. According to CoinDesk, researchers at Galaxy have identified a third wave of sweeping activity targeting these wallets, marking a significant escalation in both scope and sophistication compared to earlier phases of the attack.
The attack vector centers on weak cryptographic keys generated by vulnerable Coldcard devices. Galaxy Research traced the ongoing sweeps to this fundamental flaw in key generation, which has allowed attackers to systematically calculate private keys and drain funds from affected addresses over multiple distinct waves of exploitation. The progression to a third wave suggests the attacker has refined their operational security and expanded their target selection criteria beyond initial parameters.
A notable and concerning evolution in the attack strategy involves the deliberate shift toward targeting smaller balances. Earlier phases of the campaign reportedly focused on high-value wallets containing substantial Bitcoin holdings, but the current wave demonstrates the attacker's adaptation to harvest funds from addresses with significantly more modest balances. This tactical pivot indicates the attacker is maximizing extraction efficiency by broadening the scope beyond initially lucrative targets, effectively democratizing the risk across the entire affected user base regardless of holdings size.
Additionally, the attacker has fundamentally altered onchain fund collection methodologies. The changes in how stolen funds are consolidated and moved across the blockchain represent an operational adaptation likely designed to evade detection mechanisms or improve the efficiency of the laundering process. These modifications to the onchain footprint suggest an active, ongoing effort to counter defensive measures implemented by blockchain investigators and potential victims monitoring for suspicious transaction patterns associated with previous attack waves.
The $89 million loss figure represents a substantial increase from previous estimates, reflecting both the expanded address count and the cumulative effect of sustained exploitation over time. The 4,500 compromised addresses identified by Galaxy span a significant portion of the Coldcard user ecosystem, creating widespread uncertainty among hardware wallet users who typically assume air-gapped devices provide absolute security against remote compromise.
The ongoing nature of the campaign underscores persistent vulnerabilities in specific Coldcard firmware versions or implementation patterns. Users with devices potentially affected by weak key generation face continued risk as the attacker demonstrates persistent technical capability and willingness to extract value from compromised addresses regardless of individual balance size. The shift toward smaller targets particularly impacts retail users and long-term holders who may have assumed their holdings were insufficient to attract attention from sophisticated threat actors.
Security researchers emphasize the critical importance of verifying key generation integrity and cross-referencing addresses against the affected list published by Galaxy Research. The continuous adaptation of attack methodologies, including the strategic targeting of smaller balances and modified onchain collection behaviors, suggests the threat actor intends to maintain operations indefinitely while optimizing for total extraction volume rather than per-wallet yield, ensuring no compromised address remains safe regardless of how small the balance.