Bitcoin News
By Evie Vavasseur
1 / 15
Weak Entropy, Weak Keys. The root problem sits deep inside Coldcard's firmware.
2 / 15
90% of Stolen Bitcoin Hasn't Moved. Here's the strange part. Galaxy Research says 90% of the stolen Bitcoin is still sitting untouched.
3 / 15
Fifteen attackers. Over $130 million gone. And the bleeding hasn't stopped.
4 / 15
Galaxy Research confirmed that fifteen distinct bad actors are actively exploiting a firmware flaw inside Coldcard hardware wallets, draining Bitcoin from roughly 7,300 wallets…
5 / 15
Each wave of attacks gets its own identifier. The latest one carries the label footprint "O."
6 / 15
The root problem sits deep inside Coldcard's firmware. Instead of routing seed generation through a true random number generator, the firmware used MicroPython's pseudo-random…
7 / 15
Lower entropy means weaker private keys. Weaker private keys mean an attacker with enough computational power can brute-force their way in.
8 / 15
Coinkite co-founder Rodolfo Novak didn't dodge responsibility. He took full ownership of the bug and issued an apology. Hotfixes have been pushed out for affected models.
9 / 15
Here's the strange part. Galaxy Research says 90% of the stolen Bitcoin is still sitting untouched. All coins from the first three waves of attacks haven't moved at all.
10 / 15
Read also: Coldcards $90 Million Bitcoin Loss Exposes Hardware Wallet Security Gap
11 / 15
Hardware wallet security has always been sold on one core promise: your keys stay offline, and that keeps them safe.
12 / 15
Coinkite has been clear that hotfixes exist, but equally clear that hotfixes can't undo the past.
13 / 15
The fifteen attackers aren't operating identically. Each has its own footprint, its own pattern, its own catalog of targeted wallets.
14 / 15
Related: Bitcoin Drops to $63,350 as Coldcard Exploit Wipes $88.6 Million Across 4,585 Wallets
15 / 15
Galaxy Research keeps receiving new reports. The 73 victims confirmed as of Monday probably won't be the final count.
The Currency Analytics
Want the full story?