EX
EXBASI.COMLive Crypto Intelligence
⌘K
Back to News

Crypto News: Coldcard Exploit Reaches $89 Million Across Three Waves — Small BTC Transfers Surge to FTX-Era Highs as Self-Custody Debate Reignites

By Exbasi Intelligence
Sourced from Binance News
Crypto News: Coldcard Exploit Reaches $89 Million Across Three Waves — Small BTC Transfers Surge to FTX-Era Highs as Self-Custody Debate Reignites
The suspected Coldcard hardware wallet exploit has expanded significantly since its initial disclosure, with Galaxy Research tracking three separate attack waves totaling 1,367 BTC — approximately $88.6 million — drained from 4,585 addresses. The third wave, flagged by Galaxy Research early Sunday, drained an additional 207.7 BTC from 1,912 addresses between Friday midday and Saturday morning UTC, with the attacker now targeting smaller balances and changing the onchain collection methodology to avoid the enumeration that made earlier waves easy to map. The root cause traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the chip's dedicated hardware randomizer — leaving a bounded set of possible keys that anyone with the disclosure and sufficient compute can reproduce offline without ever touching a device. Bitcoin users responded: small-value transfers below 1 BTC reached 39,600 BTC in a single day — the highest daily level since November 2022's FTX collapse, just 300 BTC below the 39,900 BTC moved in the immediate aftermath of FTX's bankruptcy filing. The incident has reignited the fundamental Bitcoin self-custody debate, drawing responses from Galaxy Digital's Alex Thorn, Casa's Nick Neuman, and Bloomberg ETF analyst Eric Balchunas.The Three Attack Waves — How the Exploit EvolvedGalaxy Research has tracked three distinct attack waves, each with different operational characteristics that suggest either the same operator adapting after public enumeration or a second operator independently grinding the same vulnerable key space.Wave one, on July 30, drained 1,083 BTC from 1,196 addresses in 41 minutes — averaging close to one full Bitcoin per victim and processing exactly one victim per transaction. The funds were routed to a small number of shared collector addresses, making the wave straightforward to map. Wave two represented a scaling of the same methodology with similar collector address patterns. Wave three departed significantly: Galaxy flagged it as draining 207.7 BTC from 1,912 addresses — averaging just over a tenth of a Bitcoin per victim — confirming that the attacker has moved to smaller balances as the more profitable end of the vulnerable key space has been picked over. Wave three sends each victim's coins to its own unique destination rather than shared collector addresses, uses pay-to-witness-script-hash outputs — a format capable of carrying multisignature or timelock conditions — instead of the plain single-key outputs used in earlier waves, and batches an average of six victims per sweep rather than processing one at a time. Wave three also scanned only the default derivation path rather than testing multiple branches per seed.Galaxy said it is confident each wave is internally consistent with a single operator but will not link the three waves to each other. The operational evolution across waves — reduced per-victim haul, changed collection architecture, modified output format — is consistent with an attacker who processed the highest-value targets first and is now systematically working through the remaining vulnerable key space at lower profitability per address.The Technical Root Cause — March 2021 Firmware's Predictable RandomizerThe flaw traces to a specific March 2021 firmware build that routed Bitcoin seed generation to a predictable software pseudo-random number generator instead of the chip's dedicated hardware random number generator. Cryptographic security in seed generation depends entirely on the randomness of the entropy source — a hardware random number generator draws entropy from physical processes that are genuinely unpredictable, while a software pseudo-random number generator produces outputs that, while appearing random, are deterministic given knowledge of the algorithm and seed state. The March 2021 firmware's routing error left a bounded set of possible keys — a finite universe of seeds that the flawed software randomizer could have produced — that anyone with the firmware disclosure and sufficient compute can reproduce offline, testing every possible output of the flawed randomizer against every Bitcoin address that ever appeared on chain.The three-day persistence of the attack — with Galaxy's Alex Thorn warning Sunday that it remains active and urging users to move funds immediately — confirms that the bounded key space has not been fully exhausted. The declining average haul per victim across waves indicates the attacker is working through the key space in order of descending balance, having already cleared the largest wallets.39,600 BTC in Small Transfers — The FTX ComparisonCryptoQuant head of research Julio Moreno's disclosure that Bitcoin transfers below 1 BTC reached 39,600 BTC in a single day — the highest since November 16, 2022's 39,900 BTC moved in the immediate aftermath of FTX's bankruptcy — is the most significant market-structure signal from the incident. The FTX comparison is precise: November 16, 2022 was the day when retail Bitcoin holders reacted to the collapse of a centralized exchange by moving their coins out of exchanges and into self-custody at the highest rate ever recorded for small-value transfers. Friday's response — retail holders moving coins out of potentially compromised Coldcard wallets to new addresses or alternative custody arrangements — is the same behavioral signature applied to a hardware wallet failure rather than a centralized exchange failure.Moreno said he was encouraged to see users "taking action" — the 39,600 BTC in small transfers represents proactive risk response rather than passive exposure to ongoing losses. Casa CEO Nick Neuman estimated that potentially 10 times more Bitcoin was protected through self-custody action than was stolen, suggesting that the public disclosure and user response may have preserved significantly more value than was lost.The Self-Custody Debate — Three PositionsThe Coldcard incident has produced three distinct positions in the self-custody debate. Casa's Nick Neuman pushed back against claims that "self-custody is over," arguing that self-custody's distributed nature gave users time to react — a centralized exchange failure is instant and total, while a hardware wallet vulnerability allows users who become aware to move funds before the attacker reaches their specific address in the vulnerable key space. The 39,600 BTC in small transfers is Neuman's argument made numerically: users who took action protected their funds.Bloomberg's Eric Balchunas argued that Bitcoin ETFs — backed by a mature regulatory framework, institutional custody, and the operating history of the ETF industry — provide a safer alternative for users who lack the technical sophistication to manage self-custody security. The ETF argument is not that self-custody failed but that the complexity of managing hardware wallet firmware versions, derivation paths, and seed generation entropy sources is beyond the reasonable expectation of most retail investors.Industry insiders offered the most technically precise position: the Coldcard incident reflects issues with a single wallet provider's specific firmware build from March 2021 rather than a failure of the self-custody model itself. The Bitcoin protocol's security is uncompromised. The vulnerability is in Coldcard's implementation of key generation — a product-level failure that is categorically distinct from a protocol-level failure.What the Exploit Means for Bitcoin's Market StructureThe 39,600 BTC in sub-1 BTC transfers arriving simultaneously with the CoinDesk 20's 8.7% July gain and Bitcoin closing July at $63,026 describes a market where retail users are actively managing hardware custody risk while institutional capital continues its ETF-channel accumulation. The behavioral divergence — retail self-custody reassessment, institutional ETF inflows — is the specific dynamic that Eric Balchunas' observation captures: the Coldcard incident may accelerate the bifurcation between retail users who choose ETF custody for simplicity and Bitcoin holders who maintain direct self-custody with enhanced security hygiene.For the price, the exploit's market impact has been absorbed by the structural demand configuration. Galaxy's Thorn continues to track active sweeps and has urged immediate fund movement for any user with a Coldcard wallet generated on firmware from the March 2021 period or thereabouts. The bounded key space means the attack has a finite endpoint — but that endpoint has not yet been reached as of Sunday's reporting.

AI Market Prediction