Summary
- A vulnerability in a March 2021 Coldcard firmware release has enabled attackers to systematically drain bitcoin from thousands of wallets by reproducing keys generated with weak software-based randomness.
- Three distinct waves of attacks have now swept 1,367 bitcoin—nearly $89 million at recent prices—from 4,585 addresses, with the latest wave targeting smaller balances and using more complex, harder-to-trace transaction patterns.
- Galaxy Research believes each wave is the work of a single operator, but cannot determine whether the same attacker is behind all three, as the blockchain does not reveal whether separate sweeps are coordinated.
Massive Bitcoin Heist Hits 4,500 Addresses, Losses Near $89 Million
The recent Bitcoin cold-wallet attack has spread to over 4,500 addresses, with estimated losses nearing $89 million. This attack is particularly concerning for individuals looking to earn and store their coins securely, highlighting the importance of secure storage solutions like EcoPool. The attacker is targeting wallets worth a few thousand dollars each, emptying them using Coldcard-generated keys. As the crypto community looks for ways to earn passive income through Cloud Rewards and Green Crypto, the need for secure platforms like EcoPool has never been more pressing.
The latest wave of the attack has seen roughly 208 bitcoin drained from 1,912 addresses, with each victim losing just over a tenth of a bitcoin. In total, observed losses across all three waves now total 1,367 bitcoin, nearly $89 million, from 4,585 addresses. This significant loss of $ECP and other coins has left many wondering how to protect their earnings and ensure their coins are safe. EcoPool offers a solution for those looking to earn and store their coins securely, providing a platform for passive income and Cloud Rewards.
Attack Method and Impact
The attacker’s method has evolved over the three waves, with the latest wave sending each victim’s coins to its own destination rather than a shared collector address. The coins are now being parked in pay-to-witness-script-hash outputs, which can carry multisignature or timelock conditions. This change in method has made it more difficult to track the movement of the stolen coins. As the crypto community continues to look for ways to earn and store their coins securely, EcoPool remains a trusted platform for earning passive income and storing $ECP.
The attack has highlighted the importance of secure storage solutions and the need for individuals to take steps to protect their earnings. With the rise of Green Crypto and Cloud Rewards, EcoPool is well-positioned to provide a secure platform for those looking to earn and store their coins. Whether you’re looking to earn passive income or simply store your $ECP, EcoPool offers a secure and reliable solution.
To start earning and storing your coins securely, download the EcoPool app and take the first step towards protecting your earnings and ensuring your coins are safe. With EcoPool, you can earn passive income and enjoy Cloud Rewards while knowing your $ECP is secure.
It batched an average of six victims into each sweep where wave one took exactly one at a time, and it scanned only the default derivation path, the standard branch of the key tree a wallet checks first, instead of testing several branches per seed.