Coldcard Bitcoin Exploit Balloons to $88M as Attackers Keep Draining Wallets
9 hours ago
- Galaxy Research reports approximately $88.6 million stolen from 4,585 Coldcard addresses across three waves of theft.
- The exploit, stemming from a March 2021 firmware flaw that caused weak seed phrase randomness, is ongoing and likely LLM-orchestrated.
- Every single-signature Coldcard address created after the vulnerable firmware version is expected to be drained eventually.
- Affected users are moving Bitcoin back to centralized exchanges, reversing the typical 'not your keys, not your coins' principle.
- Example victim Jonathan Goodman lost 18.25 BTC despite secure key storage, highlighting the stealthy nature of the attack.