{"id":24432,"date":"2026-08-04T01:38:40","date_gmt":"2026-08-04T01:38:40","guid":{"rendered":"https:\/\/nft.runfyers.com\/index.php\/2026\/08\/04\/bitcoin-cold-wallet-attack-spreads-to-4500-addresses-as-losses-near-89-million-nft-plazas\/"},"modified":"2026-08-04T01:38:40","modified_gmt":"2026-08-04T01:38:40","slug":"bitcoin-cold-wallet-attack-spreads-to-4500-addresses-as-losses-near-89-million-nft-plazas","status":"publish","type":"post","link":"https:\/\/nft.runfyers.com\/index.php\/2026\/08\/04\/bitcoin-cold-wallet-attack-spreads-to-4500-addresses-as-losses-near-89-million-nft-plazas\/","title":{"rendered":"Bitcoin Cold-Wallet Attack Spreads to 4,500 Addresses as Losses Near $89 Million &#8211; NFT Plazas"},"content":{"rendered":"<p><\/p>\n<div>\n<p><span style=\"font-weight: 400;\">A sophisticated attack exploiting a years-old vulnerability in Bitcoin cold wallets has expanded significantly, with blockchain researchers estimating that nearly <\/span><b>$89 million<\/b><span style=\"font-weight: 400;\"> worth of BTC has now been stolen from <\/span><b>more than 4,500 wallet addresses<\/b><span style=\"font-weight: 400;\">. The campaign, which targets wallets created using vulnerable <\/span><b>COLDCARD<\/b><span style=\"font-weight: 400;\"> firmware released in <\/span><b>March 2021<\/b><span style=\"font-weight: 400;\">, has evolved through multiple attack waves and may still be ongoing.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">According to <\/span><a href=\"https:\/\/x.com\/OnchainLens\/status\/2084099439359373416\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\"><b>Onchain Lens<\/b><\/a><span style=\"font-weight: 400;\">, the exploit does not compromise hardware wallets directly. Instead, attackers are reproducing private keys generated from weak recovery seeds, allowing them to drain wallets that have remained offline for years. The incident highlights a rare but severe risk in hardware wallet security: a flaw introduced during wallet creation can permanently undermine even fully air-gapped storage.<\/span><\/p>\n<p><noscript><\/noscript><img loading=\"lazy\" decoding=\"async\" class=\"lazyload size-large wp-image-98589\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/08\/2-1-1024x576.png\" alt=\"Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million\" width=\"1024\" height=\"576\"\/><\/p>\n<p style=\"text-align: center;\"><i><span style=\"font-weight: 400;\">Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million<\/span><\/i><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Three_confirmed_attack_waves\"\/><b>Three confirmed attack waves<\/b><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">The attack first came to light on <\/span><b>July 30<\/b><span style=\"font-weight: 400;\">, when approximately <\/span><b>1,083 BTC<\/b><span style=\"font-weight: 400;\"> was stolen from <\/span><b>1,196 addresses<\/b><span style=\"font-weight: 400;\"> in just <\/span><b>41 minutes<\/b><span style=\"font-weight: 400;\">. The speed and coordination of the transactions suggested the attacker had already mapped a large portion of the vulnerable key space before launching automated wallet sweeps.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A second wave followed soon after, while a third wave over the weekend shifted focus toward wallets with much smaller balances. <\/span><a href=\"https:\/\/x.com\/glxyresearch\/status\/2083967080911470640\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\"><span style=\"font-weight: 400;\">Galaxy Research<\/span><\/a><span style=\"font-weight: 400;\"> estimates roughly <\/span><b>207.7 BTC<\/b><span style=\"font-weight: 400;\"> was drained during this latest confirmed phase, bringing total observed losses to approximately <\/span><b>1,367 BTC<\/b><span style=\"font-weight: 400;\">, worth <\/span><b>nearly $89 million<\/b><span style=\"font-weight: 400;\">, across <\/span><b>4,585 Bitcoin addresses<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Researchers also observed notable changes in the attacker\u2019s behavior.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Instead of consolidating stolen funds into a handful of collector wallets, each victim\u2019s Bitcoin was sent to a separate destination address, making blockchain tracing more difficult. The attacker also switched to <\/span><b>Pay-to-Witness-Script-Hash (P2WSH)<\/b><span style=\"font-weight: 400;\"> outputs, which support more advanced spending conditions such as multisignature or timelock scripts.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Meanwhile, each transaction now swept funds from multiple victims simultaneously, improving efficiency compared with the first wave, where addresses were emptied one by one. Galaxy said these operational changes could indicate either the same attacker adapting after public attention or another actor independently exploiting the same vulnerable wallets.<\/span><\/p>\n<p><noscript><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-98588\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/08\/3-3-1024x576.png\" alt=\"Three confirmed attack waves\" width=\"1024\" height=\"576\"\/><\/noscript><img loading=\"lazy\" decoding=\"async\" class=\"lazyload size-large wp-image-98588\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/08\/3-3-1024x576.png\" alt=\"Three confirmed attack waves\" width=\"1024\" height=\"576\"\/><\/p>\n<p style=\"text-align: center;\"><i><span style=\"font-weight: 400;\">Three confirmed attack waves<\/span><\/i><\/p>\n<h2><span class=\"ez-toc-section\" id=\"A_flaw_dating_back_to_2021\"\/><b>A flaw dating back to 2021<\/b><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">Unlike most crypto thefts involving phishing attacks or malware, this exploit originates from a firmware bug introduced in <\/span><b>March 2021<\/b><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Researchers found that one COLDCARD firmware release mistakenly generated wallet recovery seeds using a predictable software randomizer rather than the device\u2019s secure hardware random number generator. Because Bitcoin private keys are derived from those recovery seeds, affected wallets were created with significantly weaker cryptographic entropy.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Attackers can therefore reproduce the vulnerable private keys entirely offline using computing power alone, without ever accessing the victim\u2019s hardware wallet or connecting it to the internet.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The implication is particularly alarming for long-term Bitcoin holders. Once a weak recovery seed has been generated, the wallet remains vulnerable regardless of whether the device is disconnected from the internet, locked inside a safe, or stored in a bank vault.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Galaxy estimates the Bitcoin stolen during the first three confirmed waves had remained untouched for an average of <\/span><b>3.18 years<\/b><span style=\"font-weight: 400;\">, indicating many victims believed their assets were securely stored for the long term.<\/span><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Researchers_warn_of_a_possible_fourth_wave\"\/><b>Researchers warn of a possible fourth wave<\/b><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">The campaign may still be unfolding.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">On <\/span><b>August 3<\/b><span style=\"font-weight: 400;\">, Galaxy Research Head <\/span><a href=\"https:\/\/x.com\/intangiblecoins\/status\/2084079706320646300\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\"><b>Alex Thorn<\/b><\/a><span style=\"font-weight: 400;\"> identified transaction patterns consistent with what appears to be a <\/span><b>fourth attack wave<\/b><span style=\"font-weight: 400;\">. During roughly <\/span><b>2.5 hours<\/b><span style=\"font-weight: 400;\">, researchers detected <\/span><b>218 suspicious transactions<\/b><span style=\"font-weight: 400;\"> involving <\/span><b>462 suspected victim addresses<\/b><span style=\"font-weight: 400;\">, representing activity roughly <\/span><b>45 times higher<\/b><span style=\"font-weight: 400;\"> than normal.<\/span><\/p>\n<p><noscript><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-98587\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/08\/4-1-1024x576.jpg\" alt=\"Galaxy Research Head Alex Thorn\u2019s Status on X\" width=\"1024\" height=\"576\"\/><\/noscript><img loading=\"lazy\" decoding=\"async\" class=\"lazyload size-large wp-image-98587\" src=\"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/08\/4-1-1024x576.jpg\" alt=\"Galaxy Research Head Alex Thorn\u2019s Status on X\" width=\"1024\" height=\"576\"\/><\/p>\n<p style=\"text-align: center;\"><i><span style=\"font-weight: 400;\">Galaxy Research Head Alex Thorn\u2019s Status on X<\/span><\/i><\/p>\n<p><span style=\"font-weight: 400;\">After filtering out false positives and multisignature wallets, Galaxy narrowed the suspected dataset to approximately <\/span><b>709 addresses<\/b><span style=\"font-weight: 400;\"> holding around <\/span><b>448.7 BTC<\/b><span style=\"font-weight: 400;\">. However, Thorn cautioned that this latest phase has not yet been definitively confirmed because the analysis relies on transaction patterns rather than direct reports from victims.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Despite the uncertainty, Galaxy published the findings immediately because some affected users may still have an opportunity to protect their funds.<\/span><\/p>\n<h2><span class=\"ez-toc-section\" id=\"A_brief_chance_to_recover_funds\"\/><b>A brief chance to recover funds<\/b><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">Unlike earlier attacks, many suspected fourth-wave transactions were broadcast using <\/span><b>Replace-by-Fee (RBF)<\/b><span style=\"font-weight: 400;\">, a Bitcoin feature that allows an unconfirmed transaction to be replaced by another paying a higher network fee.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If victims discover the outgoing transaction while it remains in the <\/span><b>mempool<\/b><span style=\"font-weight: 400;\">, they may still be able to submit a higher-fee replacement transaction and transfer their Bitcoin to a secure wallet before miners confirm the attacker\u2019s transfer.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Thorn urged anyone who may have generated a wallet using the vulnerable firmware to immediately verify their balances and migrate remaining funds to wallets created with fresh recovery seeds.<\/span><\/p>\n<h2><span class=\"ez-toc-section\" id=\"Self-custody_faces_renewed_scrutiny\"\/><b>Self-custody faces renewed scrutiny<\/b><span class=\"ez-toc-section-end\"\/><\/h2>\n<p><span style=\"font-weight: 400;\">The incident is also influencing broader Bitcoin custody trends.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Following <\/span><a href=\"https:\/\/nftplazas.com\/bitcoins-worst-week-since-ftx-crash-signals-more-pain-ahead\/\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"internal\"><span style=\"font-weight: 400;\">FTX\u2019s collapse<\/span><\/a><span style=\"font-weight: 400;\"> in 2022, many investors embraced the principle of <\/span><b>\u201cNot your keys, not your coins,\u201d<\/b><span style=\"font-weight: 400;\"> moving assets from centralized exchanges into self-custodied hardware wallets. The COLDCARD incident shows that while self-custody removes exchange risk, it does not eliminate technical risks arising from flawed wallet generation.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">According to <\/span><b>CryptoQuant<\/b><span style=\"font-weight: 400;\">, Bitcoin transfers involving less than <\/span><b>1 BTC<\/b><span style=\"font-weight: 400;\"> briefly surged to around <\/span><b>39,600 BTC<\/b><span style=\"font-weight: 400;\"> in a single day, marking the highest level since FTX\u2019s bankruptcy. Separate blockchain analysis also shows centralized exchanges recorded <\/span><b>net inflows exceeding 15,000 BTC<\/b><span style=\"font-weight: 400;\"> on August 1, with platforms including <\/span><a href=\"https:\/\/www.binance.com\/en\" target=\"_blank\" rel=\"noopener nofollow external noreferrer\" data-wpel-link=\"external\"><b>Binance<\/b><\/a><b>, <\/b><a href=\"https:\/\/nftplazas.com\/kraken-brings-perpetual-futures-onshore-with-cftc-regulated-us-launch\/\" target=\"_blank\" rel=\"noopener\" data-wpel-link=\"internal\"><b>Kraken<\/b><\/a><b>, OKX,<\/b><span style=\"font-weight: 400;\"> and <\/span><b>River<\/b><span style=\"font-weight: 400;\"> receiving much of the incoming Bitcoin.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Meanwhile, Galaxy Research has shared roughly <\/span><b>600 suspected attacker addresses<\/b><span style=\"font-weight: 400;\"> with U.S. federal investigators, blockchain compliance firms, and cybersecurity partners to support ongoing investigations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For users who may have initialized wallets using the affected firmware, researchers say updating software alone is insufficient. The safest course of action is to create an entirely new wallet with a fresh recovery seed and immediately transfer all remaining Bitcoin, as any wallet generated using the flawed firmware should be considered permanently compromised.<\/span><\/p>\n<\/div>\n<p><a href=\"https:\/\/nftplazas.com\/bitcoin-cold-wallet-attack-losses-near-89m-4500-addresses\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A sophisticated attack exploiting a years-old vulnerability in Bitcoin cold wallets has expanded significantly, with blockchain researchers estimating that nearly $89 million worth of BTC has now been stolen from more than 4,500 wallet addresses. The campaign, which targets wallets created using vulnerable COLDCARD firmware released in March 2021, has evolved through multiple attack waves [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":24433,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true},"categories":[16],"tags":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/nftplazas.com\/wp-content\/uploads\/2026\/08\/1-4.jpg","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/24432"}],"collection":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=24432"}],"version-history":[{"count":0,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/24432\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/24433"}],"wp:attachment":[{"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=24432"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=24432"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nft.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=24432"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}