Galaxy Research: 1,367 BTC Stolen in Coldcard Mk3 Firmware Exploit

AI مارکیٹ کا خلاصہ
Galaxy Research reports 1,367.05 BTC (~$88.6M) was stolen via a Coldcard Mk3 firmware RNG weakness affecting seeds generated on versions 4.0.1+ (introduced 2021), with three coordinated sweep waves and minimal post-theft fund movement. The revision materially increases estimated losses and highlights systemic self-custody risk for single-signature users on compromised devices, potentially weighing on near-term Bitcoin sentiment and custody-provider scrutiny.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT+0.14%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
Galaxy Research says a firmware vulnerability in Coldcard Mk3 hardware wallets enabled attackers to steal 1,367.05 BTC, about $88.6 million, in three coordinated waves that affected 4,585 addresses. The new estimate is far larger than initial reports that suggested roughly 594 BTC was taken from about 500 addresses. Galaxy's on-chain review indicates a wider, more systematic operation. The biggest sweep occurred on July 30, 2026, when attackers drained 1,082.65 BTC (around $70.2 million) in 41 minutes. Galaxy found the first two waves carried nearly identical transaction signatures, including hardcoded fees of 30 sat/vB and matching batching behavior, pointing to a single operator or shared tooling. The third wave deviated from that pattern, suggesting either a different actor or a tactical change. Most of the stolen BTC has not meaningfully moved and remains concentrated in a small set of attacker-controlled addresses. Galaxy attributes the breach to predictable randomness: a weakness in the Mk3 firmware random number generator that affects versions 4.0.1 and later, introduced in March 2021. The flawed RNG produced weak, predictable seed material. With sufficient computing power, an attacker could enumerate possible seeds offline, link them to real blockchain addresses, and sweep funds from single-signature wallets without physical access to the device. Block's engineering team is credited with first publicly flagging the RNG issue. Coinkite, the maker of Coldcard, published an advisory about 30 hours after the initial sweeps began. Coldcard Mk4, Q, and Mk5 devices are not believed to share the same flaw. Users with funds tied to potentially impacted Mk3 wallets are being urged to generate entirely new seeds on unaffected models, rather than simply moving balances within the same hardware generation. Galaxy also highlighted fee behavior during the thefts: the hardcoded 30 sat/vB used in the first two waves was roughly 30 to 75 times the median fee at the time, indicating the attackers were willing to pay up for fast confirmations. For Coldcard Mk3 users running firmware version 4.0.1 or newer, the recommendation is to treat existing seeds as potentially compromised and migrate funds to a newly generated wallet on unaffected hardware. Reviewing firmware history and checking Coinkite's advisory are the immediate steps.