Coldcard losses near $114M as fourth attack wave hits
A fourth wave of sweeps against Coldcard Bitcoin wallets has pushed total losses since July 30 to roughly 1,816 BTC, near $114 million. Galaxy Research's Alex Thorn flagged a replace-by-fee window that may give some victims a last chance to recover funds.
A fourth wave of coordinated sweeps against Coldcard-generated Bitcoin addresses struck on Monday, with Galaxy Research head @intangiblecoins flagging roughly 449 $BTC pulled from 709 likely victim addresses. Researchers now estimate the attacker has moved about 1,816 $BTC, or roughly $114 million, from more than 5,200 addresses since July 30.
How the Attack Unfolded
The attack began on July 30 in a sweep that took 1,083 $BTC from 1,196 addresses in just 41 minutes. Two further waves over the weekend brought observed losses to 1,367 $BTC across 4,585 addresses. The fourth wave extended that damage further, with @intangiblecoins noting the activity averaged 13.8 sweeps per block, around 45 times the rate observed in a pre-incident control window.
The root cause is a firmware flaw introduced years ago. The vulnerability, introduced in Coldcard firmware 4.0.0 in March 2021, caused devices to skip their hardware randomness generator and fall back to predictable software-based key generation seeded by nonsecret chip data. That made supposedly unguessable seed phrases computationally reproducible, allowing attackers to reconstruct private keys without ever touching the devices.
The pattern suggests the flaw affects single-key Coldcard seeds and not multisignature setups. Drained holdings had sat dormant for an average of 3.18 years, suggesting most victims were long-term holders rather than institutions.
A Narrow Window for Victims
The fourth wave carries an unusual, if time-sensitive, lifeline. Unlike earlier waves, the latest transactions appear to use Bitcoin's replace-by-fee feature, meaning victims who spot their coins in the mempool may still be able to outbid the attacker and move their funds first. Alex Thorn, head of firmwide research at Galaxy Research, flagged the active wave and said the attackers opted into replace-by-fee, a Bitcoin feature that lets a pending transaction be overwritten by a later one paying a higher fee. Until a transaction confirms, a victim who finds their address in the mempool can pay more and move the coins out first.
Coldcard manufacturer Coinkite released emergency firmware for every affected model and told users who had generated a seed on the flawed software to move funds to a wallet address made with a fresh one. Coinkite has warned users who created seeds on Mk3 devices running firmware 4.0.1 or later, while stressing that Mk4, Q and Mk5 appear unaffected so far. Critically, fixed firmware protects newly generated seeds, but existing vulnerable seeds still require complete wallet migration.
Galaxy said it has flagged roughly 600 suspected attacker addresses to federal investigators, compliance firms and cross-industry cyber investigators. Anyone holding $BTC on a potentially affected Coldcard device is urged to check the mempool immediately and migrate funds using high fees.
Sources:
CoinDesk: Bitcoin cold-wallet losses may near $114 million as possible fourth sweep emerges
Crypto.news: Coldcard losses rise as fourth attack wave sweeps 448 BTC
The Hacker News: Coldcard Hardware Wallet Flaw Linked to Bitcoin Theft
Latest News
Read More...
Author
Crypto RichRich has been researching cryptocurrency and blockchain technology for eight years and has served as a senior analyst at BSCN since its founding in 2020. He focuses on fundamental analysis of early-stage crypto projects and tokens and has published in-depth research reports on over 200 emerging protocols. Rich also writes about broader technology and scientific trends and maintains active involvement in the crypto community through X/Twitter Spaces, and leading industry events.













