BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Alex Thorn Warns of Fourth Apparent BTC Theft Wave Targeting Coldcard Users

BitcoinWorld Alex Thorn Warns of Fourth Apparent BTC Theft Wave Targeting Coldcard Users Galaxy Digital’s Head of Research, Alex Thorn, has reported a fourth apparent wave of thefts targeting

AnonymousCryptoCompass newsroom
August 3, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for bitcoin coverage.

BitcoinWorldAlex Thorn Warns of Fourth Apparent BTC Theft Wave Targeting Coldcard Users

Galaxy Digital’s Head of Research, Alex Thorn, has reported a fourth apparent wave of thefts targeting users of Coldcard hardware wallets. In a series of posts, Thorn detailed that over a roughly two-and-a-half-hour window, 388.93 BTC moved through 218 transactions from 462 victim addresses to 216 newly created addresses. This follows an earlier incident where more than 1,359.88 BTC was stolen due to a random number generation flaw in Coldcard firmware.

Attack Pattern and Urgency

Thorn noted that some of the transactions are still in the mempool, meaning affected users may still have a window to protect their funds. He suggested using Replace-By-Fee (RBF) to attach higher fees, which could potentially override the pending transactions. The urgency is heightened by the fact that transaction frequency spiked to about 45 times the normal rate, strongly indicating an ongoing, coordinated attack.

All UTXOs involved in these transactions were created with flawed Coldcard firmware, pointing to a systematic vulnerability rather than isolated user errors. The attack appears to be exploiting a known issue that has already led to significant losses in previous waves.

Background and Impact

Earlier this year, Coldcard users suffered a major blow when a random number generation flaw allowed attackers to compromise private keys. This led to the theft of over 1,359.88 BTC. In response, Coldcard released an emergency firmware update, but reports soon emerged that some devices were bricked and failed to boot after installation, adding to the chaos.

The current wave underscores the persistent risks facing hardware wallet users, even those who rely on devices marketed for their security. For those affected, the immediate advice is to monitor the mempool and consider RBF if transactions are still pending. However, the broader lesson is the importance of staying updated on firmware patches and understanding the limitations of any security device.

Why This Matters

This incident is a stark reminder that hardware wallets, while generally secure, are not infallible. The flaw in Coldcard’s random number generation is particularly concerning because it directly compromises the cryptographic foundation of the wallet. For the broader cryptocurrency community, this highlights the need for rigorous security audits and the importance of timely firmware updates. It also raises questions about liability and the responsibility of manufacturers to ensure their products are secure by design.

Conclusion

The fourth wave of thefts targeting Coldcard users, as flagged by Alex Thorn, is a developing situation that requires immediate attention from affected individuals. The pattern of transactions and the speed of the attack suggest a sophisticated actor exploiting a known vulnerability. While the financial losses are significant, the incident also serves as a critical reminder of the evolving threats in the cryptocurrency space and the need for constant vigilance.

FAQs

Q1: What should I do if I’m a Coldcard user and suspect my funds are at risk?If you suspect your funds are at risk, first check the mempool for any pending transactions from your wallet. If you see unauthorized transactions, you can attempt to use Replace-By-Fee (RBF) to increase the fee and potentially override the transaction. Move any remaining funds to a secure wallet immediately and update your firmware to the latest version, but be aware of the recent issues with the emergency update.

Q2: How can I prevent this type of theft in the future?Always ensure your hardware wallet firmware is up to date, but verify the authenticity of updates through official channels. Consider using a multi-signature setup for large amounts, and regularly review your wallet’s security features. Additionally, stay informed about known vulnerabilities and security advisories from the manufacturer and the broader community.

Q3: Is it safe to continue using Coldcard wallets after this incident?While Coldcard has addressed the random number generation flaw with a firmware update, the recent bricking issues suggest that users should proceed with caution. It’s advisable to test the update on a wallet with a small amount of funds first, and consider alternative hardware wallets if you are concerned about the security of your assets. Always weigh the risks and stay updated on the latest security news.

This post Alex Thorn Warns of Fourth Apparent BTC Theft Wave Targeting Coldcard Users first appeared on BitcoinWorld.