Bitcoin cold-wallet losses may near $114 million as possible fourth sweep emerges

Share This Post

The flaw allowing the exploit traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the chip’s hardware one, leaving the resulting keys reproducible offline by anyone who works out the range. Coldcard manufacturer Coinkite released emergency firmware for every affected model and told users who had generated a seed on the flawed software to move funds to a wallet address made with a fresh one.

Thorn said he had no direct victim report and published his findings on pattern matching alone, choosing speed over confirmation to warn people while the transactions were still unconfirmed.

If it holds, however, the running total across four waves had reached about 1,816 bitcoin, near $114 million, from more than 5,200 addresses since July 30.

Thorn advised users to check funds, move anything off an affected device and bid the fee up.

The pattern covered blocks 960,778 to 960,792, with 218 transactions hitting 462 victim addresses at a rate of about 14 sweeps per block against 0.3 in a pre-incident control window, roughly 45 times normal.

Each of the spent coins that arrived after the Coldcard firmware boundary, and the destinations were fresh addresses with no prior history, one per victim rather than the shared collectors that made the first two waves easy to map.

Related Posts

Crypto Marketplace Xyper Enables AI Agents To Earn On-chain As Content Creators

Xyper has launched an on-chain crypto marketplace where autonomous AI...

Robinhood wins UK crypto registration ahead of new regulatory regime commencing

Crypto-friendly trading platform Robinhood (HOOD) is now registered to...

Bitcoin slips under $63,000 despite Iran deal hopes as Coldcard losses rattle market

Treasuries rallied across the curve as the oil move...

Counting down the days: State of Crypto

Senators Ruben Gallego and Thom Tillis sent a proposed...