The counter won’t stop. Set at $70 million just yesterday, the losses tied to the Coldcard flaw jumped to $114 million in the span of a single day. A fourth wave of bitcoin thefts has just be
The counter won’t stop. Set at $70 million just yesterday, the losses tied to the Coldcard flaw jumped to $114 million in the span of a single day. A fourth wave of bitcoin thefts has just been spotted — and nothing suggests the escalation is over.
In brief
- Losses linked to the Coldcard flaw jumped from $70 million to $114 million in 24 hours, with a 4th wave of 448.73 bitcoins detected by Galaxy Research.
- No Coldcard victim has yet confirmed this latest wave, whose existence rests solely on an analysis of on-chain patterns.
- The firmware fix only prevents the creation of new vulnerable seeds. Wallets already compromised before the update remain exposed as long as their funds haven’t been migrated.
From $70 to $114 Million in Stolen Bitcoin: A 4th Wave of Coldcard Thefts Has Just Been Detected
Researcher Alex Thorn of Galaxy Research spotted a pattern of fund-draining this Monday, repeated across 15 consecutive blocks at a rate roughly 45 times higher than normal. After correcting an initial count that mistakenly included multisig addresses, the tally for this new wave of attacks on Coldcard bitcoin addresses stands at 709 addresses affected for 448.73 BTC, or roughly $28 million.
Adding this amount to the three previously confirmed waves (1,367 BTC across 4,585 addresses), the total climbs to nearly 1,816 BTC — around $114 million. That’s an increase of more than 60% in a single day, whereas the $70 million figure had only been reported a few days earlier.
An important note of caution flagged by Thorn: no victim has confirmed this fourth wave so far. The figure is based on an analysis of on-chain patterns, not an official statement from those affected. Another detail that changes things: some of these bitcoin transactions were, at the time of the analysis, still unconfirmed in the mempool with the Replace-By-Fee option enabled — leaving a window for affected holders to try to regain control by outbidding on fees.
Your 1st cryptos with BitpandaThis link uses an affiliate program.Why This Flaw Keeps Causing Damage, Days After Its Discovery
What’s striking about this case isn’t just the size of the amount, it’s its ongoing progression. A flaw discovered, fixed within 48 hours by manufacturer Coinkite — and yet bitcoin losses keep piling up day after day. How to explain this paradox? The answer lies in the very nature of the bug. The firmware fix prevents the generation of new vulnerable seeds, but it does nothing to repair keys already created before it was put in place. In practice, any wallet whose seed was generated with the old, buggy firmware — a flaw dating back to March 2021 — remains exposed as long as its owner hasn’t migrated their funds to an entirely new seed.
In other words, the technical fix stopped the bleeding at the source, but not the exploitation of flaws sown over the past five years. As long as bitcoin holders remain unaware they’re affected, the attacker still has a pool of targets to exploit, one by one, at the pace of their on-chain research. This is the mechanism that explains why the amount is climbing in successive waves rather than all at once. Each new batch corresponds to a set of identified and drained wallets, not a continuous attack on a single target.
How many BTC wallets remain exposed, silently, before their owners take action? Until seed migration becomes widespread, the counter of Coldcard bitcoin attacks is likely to keep climbing. The real question is no longer whether the flaw has been fixed, but how long it will take before it stops claiming victims.