Bitcoin Wallet Sweep Campaign Expands as Hackers Drain Another 208 BTC

A new wave of Bitcoin wallet thefts has emerged, adding hundreds of BTC to an ongoing attack linked to vulnerable Coldcard-generated private keys. Blockchain researchers say the latest activity shows attackers are continuing to exploit wallets created with a flawed firmware version released in 2021.

According to Galaxy Research, the third round of wallet sweeps occurred between Friday and Saturday UTC, with approximately 208 BTC stolen from 1,912 wallet addresses. Unlike the earlier attacks that focused on high-value wallets, the latest campaign targeted addresses holding much smaller balances, averaging just over 0.1 BTC per victim.

The first attack, which began on July 30, was significantly more lucrative. During a rapid 41-minute operation, attackers drained 1,083 BTC from 1,196 addresses, averaging nearly one Bitcoin per compromised wallet. Combined with the second and third waves, total losses have now climbed to 1,367 BTC, worth around $89 million, affecting 4,585 addresses.

Researchers also observed notable changes in how the latest attack was carried out. Instead of consolidating stolen funds into a handful of common collection wallets, each victim's Bitcoin was transferred to a unique destination address. The stolen funds were then moved into pay-to-witness-script-hash (P2WSH) outputs, a transaction format commonly used for advanced spending conditions such as multisignature wallets or timelocks.

The attack strategy itself also evolved. Earlier waves generally processed one victim at a time, while the latest campaign grouped an average of six victims into each transaction. Analysts found that the attacker also limited searches to the default wallet derivation path rather than scanning multiple branches of the wallet's key structure, suggesting a more streamlined approach.

It remains unclear whether the latest activity is being carried out by the same attacker responsible for the previous sweeps or by a separate actor exploiting the same vulnerability. Blockchain data alone cannot distinguish between the two possibilities.

Galaxy Research believes each individual wave was likely conducted by a single operator but stopped short of attributing all three campaigns to the same entity.

The vulnerability behind the attacks dates back to a firmware release from March 2021. A software bug caused affected Coldcard devices to generate wallet seeds using a predictable software-based random number generator instead of the device's secure hardware randomizer.

As a result, the number of possible private keys became limited enough for attackers to recreate them offline using sufficient computing power. Because the flaw is deterministic, hackers do not need physical access to the hardware wallet to recover the affected keys.

While the pace of theft has slowed and average wallet balances have declined, researchers say the campaign is still active nearly three days after it first began. The shrinking amount stolen per wallet suggests that many of the highest-value vulnerable addresses have already been emptied, leaving attackers to work through smaller remaining balances as they continue scanning the affected key space.