
A third wave of thefts against Bitcoin wallets built on flawed Coldcard firmware ran through Saturday morning, lifting observed losses to roughly 1,367 BTC — close to $89 million — drained from 4,585 addresses since Thursday.
The size is not the interesting part. The third wave is the first one designed to be hard to follow, and that shift tells self-custody holders more about what happens next than any dollar figure does.
Smaller wallets, bigger care
Galaxy Research published the wave-three findings early Sunday. Between 12:23 UTC on July 31 and 06:42 UTC on August 1, across blocks 960,396 to 960,471, another 207.73 BTC left 1,912 addresses.
That is roughly a tenth of a coin per victim. Wave one, which opened at 01:10 UTC on July 30 and closed 41 minutes later, took 1,082.65 BTC from 1,195 addresses — nearly a full coin each. Wave two, on July 31, collected just 76.16 BTC from 1,478 addresses.
Median losses tell the same story more bluntly: 0.270 BTC in wave one, 0.010 in wave two, 0.013 in wave three. The operator is now emptying wallets worth a few thousand dollars apiece and still finding enough of them to spend ten hours sweeping.
Galaxy stresses the work is preliminary and built entirely from block data and the unspent-output set, not from any test of whether the flagged seeds were actually weak.
The anti-forensics upgrade
Waves one and two were easy to map because the attacker made them easy. Both funneled coins through a handful of shared collector addresses into P2WPKH holding wallets (pay-to-witness-public-key-hash — plain single-key SegWit outputs, fully visible on chain).
Wave three abandoned that. Each victim's coins went to their own destination, and the proceeds now sit in 293 separate P2WSH vaults (pay-to-witness-script-hash, a format that keeps its spending conditions hidden until the first time the coins move). The sweeper also batched an average of 6.37 victims per transaction, where wave one took exactly one at a time, and scanned only the default derivation path instead of testing several branches per seed. Even the fee constant changed — 30 sat/vB in wave one, 50 and 10 in wave two, roughly 200 then exactly 10 in wave three.
That is either the same crew rebuilding after being enumerated in public, or a second crew grinding the same broken key space on its own. Galaxy is confident each wave is internally one operator and refuses to connect them: "The chain does not distinguish these, nor can we."
Why were the keys guessable?
The flaw traces to Coldcard firmware shipped on March 17, 2021, around block 674,951. Not one stolen coin identified across the three waves was created before that block.
Block's engineers found the cause was a build-configuration error: Coldcard sets MICROPY_HW_ENABLE_RNG to zero because Coinkite supplies its own hardware-RNG wrapper, but the libngu cryptography library checked only whether the macro existed, not whether it was switched on. Seed generation quietly fell through to MicroPython's Yasmarang software PRNG, seeded from the chip's unique ID and timer registers and never topped up with fresh entropy.
Coinkite says Mk3 seeds ended up with about 40 bits of randomness instead of 128. On Mk4, Q and Mk5, secure-element entropy narrowed the field to roughly four billion candidates — trivial for a GPU rig. Nobody has to touch the device. You generate candidate seeds offline, derive their addresses, and check them against the public UTXO set.
A retail wipeout, and the coins have not moved
The victim profile is individual, not institutional. Some 3,122 of the 4,585 drained addresses lost under 0.1 BTC, while 288 addresses that lost more than 1 BTC account for around 960 BTC of the total. The largest single address gave up 51.07 BTC. The median victim address had sat untouched for about three and a half years — exactly what long-term cold storage looks like.
All 1,366.39 BTC now under attacker control, spread across 596 addresses, remains completely unspent. Galaxy is watching seven wave-one and wave-two addresses holding 1,158.81 BTC, plus all 293 vaults. The first spend from any vault reveals its script, and a cosigner key reused across two of them would be the link that investigators currently cannot prove.
Two adjacent signals are worth noting without over-reading. Exchanges took in a net 11,163 BTC on July 31 — River 3,679, Binance 3,224, Kraken 2,848, OKX 1,291 — and wallets dormant from 2010 to 2017 shifted about 306 BTC between July 30 and August 1. Neither can be tied to the sweeps from public data, and both may simply be holders who no longer trust their setup.
What should Coldcard owners do now?
Coinkite shipped emergency firmware on July 31: 4.2.0 or later for Mk3, 5.6.0 or later for Mk4 and Mk5, and 1.5.0Q or later for Q. CEO Rodolfo Novak apologised publicly and said the company takes "full accountability for the firmware bug."
Updating fixes nothing you already own. A seed generated under the flawed build stays guessable forever, and restoring it onto patched firmware or a different wallet carries the weakness straight across.
The migration path is unglamorous: install the fixed firmware, generate an entirely new seed on it, send a small test amount to an address from that new seed, confirm you can spend it, then move everything else. Keep the old backup until the transfer is finished and verified.
Seeds created with at least 50 rolls of a fair die, or protected by a strong BIP-39 passphrase, are considered outside this issue because the user's own randomness swamped the broken generator. Multisig setups where the Coldcard key was one signer among several also survived.
The falling average haul suggests the profitable end of the vulnerable key space is picked over. That is cold comfort. Wave three's median take of 0.013 BTC is the clearest evidence yet that no balance is now small enough to be beneath the scanner's notice — and the sweeping had not stopped three days in.