Suspected Fourth Wave of Coldcard Bitcoin Exploit Hits 462 Addresses

AI مارکیٹ کا خلاصہ
A suspected fourth coordinated sweep targeting vulnerable Coldcard-generated Bitcoin addresses is moving large BTC amounts at an unusually high transaction cadence, reinforcing self-custody operational risk. Confirmed losses across prior waves are already substantial, and Coldcard's admission that patched firmware only protects newly generated seeds implies legacy wallets may remain exposed. Near term, this can drive urgent fund migrations, raise on-chain fee pressure, and weigh on crypto risk sentiment.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT-0.65%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Galaxy Research head Alex Thorn said early Monday that a suspected fourth coordinated wave is now targeting Coldcard users. Thorn flagged 218 transactions across blocks 960,778 to 960,792 that collectively moved more than 380 BTC from 462 addresses believed to belong to victims into 210 newly created destinations. He said the activity averaged 13.8 sweeps per block—about 45 times the pre-incident pace of 0.3—and that the transfers matched patterns tied to vulnerable Coldcard-derived addresses. Onchain Lens put confirmed losses at $88.6 million following three confirmed waves, attributing 1,367.05 BTC drained from 4,585 addresses. Coldcard said Sunday it has paused shipments, destroyed remaining devices with the flawed firmware, and told users that patched firmware only protects newly generated seeds. Why it matters: A failure in a wallet's random number generator can force self-custody users into rapid fund migration if additional vulnerable addresses remain exposed. Market sentiment: Bearish, stress-on, tech-driven, volatile. Reason: A likely fourth wave increases confidence stress around self-custody security. Similar past cases: In August 2022, a Solana wallet-drain incident was traced to Slope. CoinDesk reported the exploit likely involved about $6 million in stolen user funds, underscoring how wallet-side key handling failures can trigger rapid migrations and distrust. What's different this time: The Coldcard incident centers on a hardware wallet, and the fourth wave is described as likely rather than confirmed. Ripple effects: An RNG flaw can spread through confidence channels as users reassess older self-custody setups until funds are moved to fresh seeds. Continued appearance of similar transactions in the mempool could intensify fee competition, accelerate urgent migrations, add congestion, and raise the risk of user mistakes. A clear response from Coldcard could limit spillover to affected devices and exposed addresses. Opportunities: If RBF fee races enable victims to outbid attacker transactions, rapid migration to fresh seeds could cap operational losses. Clearer, coordinated recovery guidance from Coldcard could reduce user-error risk by discouraging improvised actions. Risks: If a fourth wave is verified and lifts the final tally, reducing BTC exposure on potentially vulnerable seeds becomes a defensive priority. Faster second-hop movement may also reduce recovery odds.