Coldcard wallet exploit losses surpass $130M as 15 attackers siphon BTC

AI مارکیٹ کا خلاصہ
Galaxy Research reports an active theft wave targeting Coldcard users, with estimated losses exceeding $130M across ~7,300 wallets due to weak seed entropy from faulty firmware. Because compromised seeds cannot be fixed by updating firmware, affected BTC may remain vulnerable until migrated, sustaining custody risk. The incident can drive near-term risk-off positioning, heightened scrutiny of self-custody hardware, and potential volatility if stolen coins begin moving from previously dormant addresses.
اثر کی سطح
● ہائی
متاثرہ اثاثے
BTC/USDT+1.08%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Galaxy Research said Tuesday that 15 distinct attackers are actively draining bitcoin from Coldcard users' hardware wallets. The firm estimates losses now exceed $130 million across roughly 7,300 wallets, and said it had heard from 73 victims as of Monday. Galaxy Research added that a 15th attacker appeared overnight after a user reported losing less than 1 BTC. That activity was tied to 12 BTC taken from 126 wallet addresses. Coinkite attributed the incident to faulty firmware that diverted seed generation to MicroPython's software fallback, reducing seed strength. The company said seed phrases on Coldcard Mk2 and Mk3 were left with about 40 bits of entropy, while Mk4 seeds had about 72 bits. Coinkite has shipped hotfixes for affected models, but warned the threat remains active and that firmware updates do not fix seeds created under the vulnerable firmware. Why it matters: Weak seed generation can turn public-address scanning into a persistent custody risk. Losses may continue until exposed funds are moved to wallets created with fresh, secure seeds. Market sentiment: Bearish, stress-on, event-driven, de-risking. Traders may treat the episode as an ongoing custody stress event given the scale and the fact that the attacks are still active. Similar past cases: In 2023, Atomic Wallet users sued over more than $100 million in crypto losses tied to a wallet hack, highlighting how wallet-compromise events can drive large user losses and prolonged recovery disputes (Bloomberg Law). The Coldcard situation differs in that it centers on weak seed generation in certain hardware-wallet firmware. Ripple effects: Weak seed generation can extend risk beyond an initial theft wave because attackers can continuously scan public addresses and race owners to move funds. If affected users rotate funds to newly generated seeds, the active attack surface could shrink. If previously dormant stolen coins begin moving, market focus could shift from custody risk to potential liquidation risk. Opportunities and risks: - Opportunities: Additional attribution of attacker footprints by Coinkite or Galaxy Research could strengthen the signal to move funds away from affected seeds as a direct custody-risk reduction step. - Risks: If affected owners delay migrating BTC to fresh wallets, attackers can continue draining vulnerable addresses and custody risk remains elevated.