Bitcoin wallets linked to Coldcard hardware devices have been hit by a fresh surge of thefts, pushing total losses past 1,367 BTC, or nearly $89 million. Galaxy Research has identified a third wave of attacks targeting addresses generated on Coldcard wallets, with 207.7 BTC stolen in this latest round alone.

The initial two waves shared many traits: stolen funds moved to a few common collection addresses, attackers targeted multiple wallet derivation paths, and transactions used P2WPKH addresses. The 27-hour gap between these attacks and their structural similarities hinted they might be the work of the same group, though some differences in transaction fees and replace-by-fee signals left room for doubt.

Signs Point to a New Attacker or Evolving Tactics

The third wave appears quite distinct. Instead of funneling stolen coins to shared collection points, each victim’s funds were sent to separate addresses. These addresses used P2WSH scripts rather than the P2WPKH seen before, and each transaction aggregated multiple victim addresses, averaging over six per dump. plus this wave focused solely on default derivation paths, unlike earlier attacks.

Galaxy Research suggests two possibilities: either the same attacker revamped their tools to complicate blockchain tracing or a new threat actor emerged after details of the Coldcard vulnerability became public. This evolving attack pattern complicates efforts to track and recover the stolen Bitcoin.

Coldcard’s ongoing security issues follow broader concerns in crypto security highlighted recently and come amid a year where phishing scams have drained billions from Bitcoin holders. The magnitude of these losses shows the urgent need for hardware wallet users to stay vigilant and update security practices.

This article is for informational purposes and does not constitute financial advice.