Galaxy: Coldcard RNG Firmware Flaw Linked to ≥1,596 BTC in Losses; Total Could Near $130M
AI مارکیٹ کا خلاصہ
Galaxy Research estimates the Coldcard RNG firmware bug has enabled theft of at least 1,596 BTC, with a suspected fourth wave potentially lifting losses to ~2,055 BTC. The vulnerability stems from deterministic seed generation on certain firmware versions, undermining hardware-wallet trust and raising near-term custody risk perception for Bitcoin holders. With ~90% of stolen BTC still unmoved and law enforcement engaged, markets will monitor for coin movement and additional exploit attempts.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+0.41%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Galaxy Research says a vulnerability affecting Coldcard hardware wallets has already resulted in at least 1,596 BTC stolen, with total losses potentially rising to roughly 2,055 BTC (about $130 million) if a suspected fourth wave of thefts is confirmed.
In a post on X, Galaxy said it has mapped 1,596 BTC taken from around 7,300 addresses across three confirmed waves of attacks, plus 14 smaller related incidents. The firm is not yet including a suspected fourth wave in its confirmed total, citing the need for victim reports to validate what it sees onchain. If those signals are tied to the same exploit, Galaxy estimates overall losses would reach about 2,055 BTC.
How Galaxy built the estimates
Galaxy said its onchain mapping supports the 1,596 BTC figure for the three confirmed waves. A prior, broader blockchain-only review suggested four-wave movement of about 1,815.75 BTC, but the firm has refined its confirmed attribution while keeping a larger, still-unverified estimate for the suspected fourth wave.
Analysts flagged the potential fourth wave on Aug. 3 after identifying transaction patterns similar to earlier attacks. Galaxy's running estimate for the suspected wave is about 448.7 BTC from 709 possible victim addresses, while noting that onchain data alone cannot confirm every victim or prove whether a single operator executed all thefts.
Galaxy said blockchain activity indicates the suspected fourth wave is "substantially comprised of" one attacker, giving the firm medium-to-high confidence while it awaits direct confirmations.
What went wrong
Coinkite, the maker of Coldcard, disclosed the flaw last week and traced it to a firmware change in March 2021. During integration of a new cryptographic library, the device's seed-generation process inadvertently fell back to a deterministic pseudorandom generator provided by MicroPython, rather than using the hardware-backed true random number generator.
Because the hardware RNG was still used elsewhere in the firmware, basic internal checks did not catch the change in the entropy source.
Independent review
Block's Bitcoin engineering and security team independently reviewed the firmware and reached the same conclusion: affected firmware used the deterministic MicroPython fallback for seed creation instead of the STM32 hardware RNG.
Coinkite estimates effective entropy on impacted devices fell well short of the intended level: about 40 bits for some Mk2/Mk3 units, and roughly 72 bits for vulnerable Mk4/Mk5 and Coldcard Q models, versus a target of 128 bits.
Attack patterns and investigation
Galaxy said most stolen balances were dispersed across many newly created addresses instead of being consolidated into a single collector wallet. Some funds were later moved through second-hop transactions that complicate tracing.
During the suspected fourth wave, Galaxy observed activity jump to roughly 13.8 wallet sweeps per Bitcoin block, up from about 0.3 sweeps per block previously.
Galaxy estimates around 90% of stolen BTC remains unmoved onchain. None of the coins taken in the first three confirmed waves have moved since the thefts, a window that gives investigators time to monitor and respond.
Galaxy said it is working with U.S. federal law enforcement, crypto exchanges, and cyber-investigation groups, and is sharing confirmed attacker and victim addresses as the investigation expands. The firm warned that additional attackers could attempt to exploit the same vulnerability while affected wallets remain in use, making identification of attacker-controlled addresses critical for exchanges and authorities if funds begin moving.
Guidance for Coldcard users
Galaxy and Coinkite urged users to move funds out of any wallets created with vulnerable firmware and to generate entirely new seed phrases only after installing patched firmware.
Coinkite has released emergency updates for affected models, including v4.2.0 for Mk2/Mk3, v5.6.0 for Mk4/Mk5, and v1.5.0Q for Coldcard Q, and said it has destroyed remaining inventory containing the vulnerable firmware.
Key caveats from Coinkite
Coinkite said the update only protects wallets created after applying the fix. Existing seeds generated under vulnerable firmware remain exposed and must be replaced.
The company recommends generating a completely new seed on a patched device, verifying a receiving address, sending a small test transaction, and transferring the full balance only after the test succeeds.
Wallets created using at least 50 fair private dice rolls are not vulnerable to this RNG issue alone, and a strong BIP39 passphrase adds protection. Coinkite still recommends migration because the original seed material remains weak.
Other recovery notes
Galaxy previously noted that users who notice an unconfirmed theft transaction may have a narrow chance to attempt replacement via Bitcoin's Replace-by-Fee (RBF) mechanism. That approach only applies before the original transaction is mined and does not guarantee recovery.
Bottom line
The episode underscores how firmware-level errors can undermine hardware wallet security. Coldcard owners are advised to check firmware versions, treat seeds created on vulnerable versions as compromised, and migrate only after applying Coinkite's patches and following the firm's migration checklist. Galaxy said its ongoing onchain mapping and coordination with law enforcement aim to track attacker addresses and limit further losses as the probe continues.