On-chain sweeping operations targeting specific models of Bitcoin hardware wallets continue to accelerate. Recent monitoring data reveals that attackers executed a new wave of batch transfers over the weekend, siphoning off approximately 200 Bitcoin from nearly 2,000 distinct addresses in a single operation. Spanning from Friday through Saturday, the cumulative drained assets remain substantial. Across the first three waves, the number of impacted addresses has surpassed 4,500, with a total of nearly 1,400 Bitcoin moved out, equating to close to $90 million.
In contrast to the blunt, bulk-consolidation tactics used in earlier phases, the current campaign exhibits pronounced stealth characteristics in its fund routing. Instead of funneling stolen assets into a handful of public addresses, operators now assign a unique destination output to each compromised address, encoding the transactions with complex script conditions. This technical shift not only complicates on-chain forensic tracking but also signals a refinement in the attackers’ selection algorithms. Analysis shows that the volume of victims processed per batch has risen, while the scanning scope has been precisely narrowed to the hardware wallets’ default key derivation paths, deliberately bypassing alternative branches. This targeted pruning strategy underscores a significant leap in the malware’s matching efficiency.
The root cause of this security breach traces back to a critical firmware update deployed two years ago. During that iteration, the secure seed generation process was inadvertently delegated to a software-based pseudo-random number generator, displacing the device’s dedicated hardware entropy module. This architectural flaw drastically reduced the effective key search space, enabling threat actors to derive private keys via offline computation without ever interacting with the physical hardware. While industry analysts suspect the same syndicate has orchestrated successive waves, the attack pipeline remains active. Notably, as high-value addresses are systematically depleted, the average payout per transaction has followed a steady downward trajectory. Initial waves yielded an average of roughly one Bitcoin per compromised wallet, whereas recent batches have dwindled to approximately 0.1 BTC, confirming the attackers’ strategic focus on exhausting premium targets first.
The proliferation of these targeted exfiltration campaigns is severely damaging the credibility of hardware wallet manufacturers. An increasing number of investors are now scrutinizing their key management practices, firmware integrity, and derivation path settings. Within the broader digital asset ecosystem, the resilience of foundational cryptographic protocols has once again taken center stage. This incident has underscored the indispensable role of hardware-based random number generators, the urgency of timely vendor security patches, and the risk-mitigation advantages of multi-signature setups. Market participants and on-chain security researchers are closely monitoring whether additional attack vectors will emerge and if automated scripts will increasingly target low-balance tail addresses.





