๐Ÿ“… Sunday, 6 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Peretas Coldcard Kuras 1.367 BTC dalam Tiga Gelombang - dan Update Software Saja Tak Bisa Selamatkan Dana Anda

Coldcard Hackers Drain 1,367 BTC in Three Waves - And a Software Update Alone Won’t Save Your Funds

The losses continue to mount. A total of 1,367 BTC, or roughly $89 million, has been drained from 4,585 Bitcoin addresses belonging to Coldcard hardware wallet users across three consecutive exploit waves. The first wave on July 30 swept 1,083 BTC from 1,196 addresses in just 41 minutes, averaging nearly 1 BTC stolen per victim.

A recent report by Galaxy Research detected a third wave operating between Friday afternoon and early Saturday morning UTC. During this phase, hackers scooped up an additional 208 BTC from 1,912 addresses. The pattern differed: the average haul dropped to 0.1 BTC per victim. The shift toward smaller balances indicates that the lucrative keyspace is beginning to dry up. These findings corroborate a report by WatcherGuru, which stated that total losses from the incident had surpassed $88 million and garnered 1,053 likes on the X platform.

New Tactics Target Smaller Balances

In addition to targeting smaller amounts, the third-wave operators altered their money laundering patterns. Each victim’s funds were sent to a unique destination address rather than being pooled into a single shared wallet like on the first day. They utilized the pay-to-witness-script-hash output format and swept an average of 6 victim wallets simultaneously per transaction round.

Despite the clean execution, analysts from Galaxy’s research team stated there is no evidence linking the three attack waves into a single centralized operation. Based on on-chain activity trails, the research team concluded that each wave was executed by an independent internal operator with no connection to other groups.

Root Cause Dating Back to 2021

The entry point for this multi-million dollar hack stems from legacy software. It all traces back to a Coldcard firmware update released in March 2021. The system at the time used a software-based randomizer with a predictable algorithm instead of relying on a dedicated hardware random number generator (RNG) chip. Coinkite co-founder Rodolfo Novak publicly acknowledged that the bug in the old firmware is part of his company’s responsibility.

The hardware wallet manufacturer has released a patch to eliminate the software backdoor flaw. However, the structural issue remains unresolved. Seed phrases generated while using the vulnerable firmware will permanently carry an inherent weakness. Updating the user’s physical device to the latest software version does not patch the flaw in old seeds whose number sequences are already predictable.

Responding to this massive exploit, Changpeng Zhao took to his X account to remind Bitcoin holders that no asset custody system is entirely invulnerable. His brief message summarized the reality of crypto exploits: “Nothing is 100%.”

For users of these hardware wallets, simply clicking the update button on a computer is not enough. You must generate a fresh, clean seed phrase from scratch and transfer all crypto assets to that address as soon as possible before a fourth wave of hackers targets your balance.

Reported by CoinDesk.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share