A sophisticated attack targeting cold wallets generated by Coldcard hardware devices has escalated rapidly, affecting approximately 4,500 addresses with total losses approaching $89 million. Galaxy Research identified a third wave of sweeps, marking a shift in the attacker's tactics and scope.

The compromise traces back to weak key generation in certain Coldcard firmware versions. The attacker exploited this vulnerability by targeting addresses holding Bitcoin that users believed were secure in offline storage. The first and second waves focused on larger balances, but the latest iteration pivots toward sweeping smaller amounts across a dramatically wider range of addresses.

Researchers observed the attacker changing fund collection methods to complicate tracking and recovery efforts. Rather than consolidating stolen Bitcoin into single addresses, the attacker now distributes recovered coins across multiple addresses, creating a more fragmented onchain footprint that makes tracing and freezing funds substantially harder.

The scale of the operation reflects serious risks in hardware wallet implementations. Coldcard, produced by Coinkite, generates keys locally but apparently failed security audits in certain firmware releases. Users who generated addresses with affected versions face exposure even if they followed best practices for cold storage deployment.

The attack underscores how supply chain vulnerabilities and firmware flaws can compromise hardware devices that exist specifically to isolate keys from internet-connected systems. Unlike exchange hacks where centralized platforms hold custody, these losses fall directly on individuals who believed their offline storage approach provided adequate protection.

Victims have limited recourse. On-chain recovery requires identifying and blocking stolen funds before moving them through mixers or exchanges, but the attacker's evolving consolidation strategy makes this increasingly difficult. Coldcard users affected by the vulnerable firmware versions face a choice between accepting losses or attempting long-shot recovery efforts.

The incident signals broader concerns about hardware wallet security auditing and the incentives for manufacturers to maintain firmware integrity across versions.