A large-scale hacking campaign targeting Coldcard hardware wallets has resulted in record losses for cryptocurrency holders. According to my latest analysis, the total damage has exceeded $115 million. Since July 30, attackers have withdrawn 1778.58 BTC from 8680 addresses. These figures reflect not just a single incident, but a systemic security issue that developed in waves.

Based on network data, I have identified the 10 largest groups involved in the fund withdrawals, but a significant portion of the addresses still remain unidentified with specific owners. This highlights the complexity of tracking and recovering assets in such cases.

The key clue — the 2021 firmware

My analysis showed that all stolen bitcoins were created after the release of the vulnerable firmware version on March 17, 2021 (block 674,951). I did not find a single affected coin issued before that date. This is also confirmed by data from the 3598 addresses reported by victims: the earliest of them dates back to March 22, 2021.

This pattern directly points to the attack vector. The vulnerability was embedded in key generation, and therefore bitcoins on these devices could only have appeared after the problematic update was installed. The average holding period of funds on the drained addresses was about 1292 days (approximately 3.5 years), indicating that the attackers patiently waited for the right moment.

Anatomy of the attacks: the first wave was the most devastating

The first wave of attacks caused the greatest damage, leading to losses of $70.2 million, accounting for 61% of the total amount. Notably, the withdrawal speed at that time even alarmed the founder of Binance, Changpeng Zhao (CZ). The funds were moved within nine consecutive blocks in just 41 minutes. The operator used a fixed fee of about 30 satoshis per vByte, draining one address per transaction.

In the first wave, 1195 wallets were affected, and the stolen assets were divided among four "collectors." For comparison, the Footprint E wave affected more addresses (2147) and could combine up to 795 vaults in a single transaction. Interestingly, a significant portion of the funds from the first wave remained untouched — 1082.57 BTC out of 1082.65 BTC are still stored in place, while almost all Footprint E funds (209.94 BTC) have already been moved.

Assets from the third wave followed a different pattern: first to regular wallets, but now 207.73 BTC are locked in script-based "vaults." Meanwhile, only 192 people have officially reported losses totaling 714.81 BTC (40.2% of all stolen funds). The median loss is about 1.03 BTC, and the maximum reaches 58.97 BTC. Another 6890 addresses with 1063.76 BTC remain unlinked to owners.

My comment: This situation is another reminder that even "cold" storage is not a panacea. A vulnerability in the supply chain or firmware can negate all the advantages of a hardware wallet. Investors should diversify risks, use devices from different manufacturers, carefully monitor updates, and also verify the origin of their coins.