CoinDesk reports that a bitcoin cold-wallet attack has now affected 4,500 addresses with losses approaching $89 million. Galaxy Research identified a third wave of the attack linked to weak keys generated by Coldcard wallets, with the attacker beginning to target smaller balances and altering their onchain fund collection methods.
If this traces to weak key generation rather than device compromise, the lesson for anyone shipping wallets is that entropy quality and RNG audits matter as much as the secure element story you market. Worth checking whether your own key-gen paths depend on any library or firmware version implicated here, and whether you can detect and warn users with affected addresses. The attacker moving to smaller balances suggests they've automated the sweep, so the window to migrate at-risk funds is likely short.
The headline and summary above belong to CoinDesk; the full story is theirs and lives on their site. Only the commentary is ours.