Galaxy Research has announced the discovery of a third wave of attacks, believed to be targeting addresses created on Coldcard devices. According to available data, the latest wave resulted in the withdrawal of 207.7294 $BTC, bringing total losses to 1367.05 $BTC, or approximately $88.6 million USD, across 4,585 addresses.
According to the research company, the first two waves of attacks exhibited mostly similar behavior on the blockchain. In both waves, funds were transferred to a small number of common collection addresses, used P2WPKH addresses, and targeted wallets created based on different derivation paths. The roughly 27-hour interval between the two waves and the similarity in transaction structure suggest the attacks could have been carried out by the same individual or group.
However, Galaxy Research emphasized that there were differences in transaction fees and "fee replacement" signals between the first two waves, so definitively proving the involvement of the same malicious actor was not possible.
Third Wave May Indicate a Different Malicious Actor.
According to Galaxy Research data, the third wave of attacks differs from the two previous ones in almost all measurable behavioral characteristics. Instead of using common collection addresses like in the first attacks, the third wave created a separate target address for each victim.
It was noted that the bitcoins stolen in the third wave were stored on P2WSH addresses, not P2WPKH addresses, and that an average of 6.37 victim addresses were aggregated in each sweep. In contrast, the first wave of attacks targeted only one victim address per transaction. Furthermore, it was stated that the third wave scanned only addresses along the standard generation path.
Researchers noted that these changes could be due to the same malicious actor redesigning their tools to hinder blockchain transaction tracking. However, it was also noted that a second malicious actor targeting the same vulnerable key pool may have emerged after information about the Coldcard vulnerability became public.
Galaxy Research reported that blockchain data does not allow for a clear distinction between these two scenarios. The company stated that while it is certain that each wave of attacks was managed by a single operator, it cannot be said with confidence that all three waves were related to the same malicious actor.
Bitcoins on Malicious Actors' Addresses Not Yet Moved.
According to Galaxy Research calculations, the malicious actors control a total of 1,366.3865 $BTC. It is claimed that not all of the final malicious actor addresses to which these bitcoins, worth approximately $88.6 million, were transferred have yet been spent on the blockchain.

A block-by-block analysis showed that addresses were broadcast to the network en masse during the attack waves. The absence of any broadcast operations in intermediate blocks within each wave attributable to the malicious actors' actions indicates that operations were sent to the network in batches, not continuously.
It was noted that losses were primarily concentrated in wallets with a balance of less than 1 $BTC by address count, but addresses with larger balances were crucial in terms of the total amount. Galaxy Research estimated that this distribution more closely resembles individual users' own custodial wallets rather than institutional custodial services.
The research also revealed that the vulnerable Coldcard software was released on March 17, 2021, around Bitcoin network block 674,951. Galaxy Research stated that none of the bitcoins identified as stolen in the first three waves of attacks were created before this block.
*This is not investment advice.
end-content






