๐Ÿ“… Sunday, 6 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Coldcard Kebobolan $88,6 Juta dalam Tiga Gelombang - dan Peretasnya Masih Menguras Dompet Korban

Coldcard Drained of $88.6 Million in Three Waves - and Hackers Are Still Emptying Victims’ Wallets

Coldcard wallet users are facing a serious crisis as Galaxy Research raised its loss estimate to 1,367.05 BTC, worth $88.6 million, drained from 4,585 addresses. Alex Thorn of Galaxy Digital emphasized that the exploit remains active at the time of writing, urging device owners to move their funds immediately.

The incident unfolded across three consecutive waves. The first wave struck on July 30 between 01:10 and 01:51 UTC, siphoning 1,082.65 BTC from 1,196 addresses. This initial attack occurred 30 hours before Coldcard manufacturer Coinkite issued a public alert. A day later, the second wave pulled 76.16 BTC from 1,478 addresses. On-chain trails show the first two attacks shared the same consolidation address and derivation path, strongly indicating they were orchestrated by the same entity.

The third wave seized 207.73 BTC from 1,912 addresses. This time, the attacker sent each victim’s funds to separate addresses, with multiple victims batched per transaction. This new pattern has made Galaxy hesitant to conclude that a single actor orchestrated all three waves. Retail panic was clearly visible across the network. CryptoQuant head of research Julio Moreno noted that sub-1 BTC Bitcoin transfers hit 39,600 BTC in a single day, marking the highest level of panic since the FTX collapse in November 2022, which saw 39,900 BTC.

Code Flaw from Three Years Ago

The turmoil stems from a firmware flaw dating back to March 2021. The bug caused devices to fall back on MicroPython software that generated predictable random numbers whenever the primary hardware random number generator failed.

Vulnerable models include Mk2 and Mk3 running firmware versions 4.0.1 through 4.1.9. Early Mk4, Q, and Mk5 variants were also impacted because they only generated 72 bits of entropy, well below the 128-bit standard. Users who generated their seed using 50 manual dice rolls are safe from the exploit. Using a strong BIP-39 passphrase also mitigates risk, but Coinkite still urged everyone to migrate their wallets immediately.

Evacuating funds requires caution. Coinkite instructed users to install new firmware, generate a new seed, verify backups, and test with a small transaction before transferring their entire balance. The $88.6 million figure is only an initial estimate from Galaxy, not the final total loss.

One Product Failed, Not the Entire System

The massive losses have reignited the debate over crypto custody. Bloomberg analyst Eric Balchunas argued the incident proves Bitcoin ETFs are safer for the general public. The self-custody camp strongly pushed back. Casa CEO Nick Neuman highlighted that the amount of Bitcoin held by Casa users is ten times greater than the total Coldcard loot. The community views the incident purely as a single manufacturer’s flaw, not a failure of the self-custody philosophy.

This legacy code disaster leaves behind an expensive lesson. When a point of trust is compromised, a small loophole in outdated software has proven capable of siphoning millions of dollars with no resistance.

Reported by crypto.news.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share