Galaxy Research identifies third wave of sweeps targeting smaller balances as attacker changes onchain collection method
Briefing
The Libbitcoin Explorer weak-key vulnerability (CVE-2023-39910) drained roughly $900,000 from wallets whose private keys were generated using insufficient entropy. The Coldcard case follows the same mechanism: flawed key generation rather than protocol compromise, meaning no amount of network-level security prevents the drain once keys are exposed.
The Slope wallet exploit on Solana compromised approximately 9,000 wallets and drained roughly $8 million by exposing seed phrases through a logging vulnerability in the wallet software itself. That event established the precedent that hardware and software wallet firmware flaws, not smart contract bugs, represent the highest-severity custody attack vector.
Ledger's customer data breach exposed 270,000 user records, triggering phishing and physical threats against hardware wallet holders. While that was a data leak rather than a key-generation flaw, it demonstrated that hardware wallet brand damage from security incidents is severe, persistent, and directly benefits competitors in the near term.

Apple is facing a lawsuit over a fake Sparrow Wallet app that drained $1.8 million in Bitcoin from three users, with allegations that Apple retained the fraudulent app after an $875,000 theft was reported. Combined with the Coldcard exploit, this establishes a multi-vector custody failure pattern spanning both hardware and app-distribution channels within the same news cycle.

Zcash's Ironwood upgrade activated to retire the Orchard shielded pool after a counterfeiting vulnerability went undetected for four years, gating $1.7 billion in assets. The Orchard and Coldcard incidents together signal a period of compounding infrastructure credibility failures across crypto, which systematically advantages institutional custodians over self-custody solutions.

The BlackRock-Coinbase-Strategy $15M quantum-proofing consortium and Galaxy's $5M initiative both assume Bitcoin's cryptographic foundations remain intact at the protocol level. The Coldcard exploit is a reminder that the near-term attack surface sits at the key-generation and wallet-firmware layer, not the protocol layer, making the quantum research focus strategically misaligned with the current threat vector.
See Indexa more often on Google
Mark Indexa as a preferred source — your Top Stories will surface more Indexa coverage.

4 days ago