A fourth wave of suspected attacks targeting Coldcard hardware wallet users has been identified, Galaxy Research's Head of Research Alex Thorn (@intangiblecoins) reported on August 3. The lat
A fourth wave of suspected attacks targeting Coldcard hardware wallet users has been identified, Galaxy Research's Head of Research Alex Thorn (@intangiblecoins) reported on August 3. The latest activity moved approximately 388.9 $BTC across 218 transactions, affecting 462 potential victim addresses within a matter of hours.
A Firmware Flaw at the Root of the Attacks
The attacks trace back to a vulnerability in a March 2021 Coldcard firmware release that enabled attackers to systematically drain Bitcoin from thousands of wallets by reproducing keys generated with weak software-based randomness. In a properly functioning hardware wallet, seed phrases are created through a dedicated random-number generator. Coldcard's firmware was meant to draw that number from a dedicated hardware randomness generator, but an internal build setting told it to skip that generator. Key generation then fell through to a basic software substitute seeded from the chip's serial number and its clock registers.Because every Bitcoin private key is derived from that seed, attackers who can recreate it can derive the same wallet and sweep funds without ever touching the physical device.
Coinkite released patched firmware, but seeds already generated under vulnerable versions remain compromised and cannot be fixed by an update.Security firms warn that more wallets could be hit because owners cannot reliably tell if their seeds were generated on vulnerable firmware.
Scale of Losses and Ongoing Danger
Prior to the fourth wave, Galaxy Research had identified three waves of thefts in which 1,367 BTC, around $88.6 million, was drained across 4,585 addresses.In the fourth wave alone, Thorn detailed that over a roughly two-and-a-half-hour window, 388.93 BTC moved through 218 transactions from 462 victim addresses to 216 newly created addresses.
Thorn noted that some of the transactions are still in the mempool, meaning affected users may still have a window to protect their funds. He suggested using Replace-By-Fee (RBF) to attach higher fees, which could potentially override the pending transactions.Thorn described the sweeps as deliberate and likely AI-orchestrated, warning that every single-sig Coldcard address created after the March 2021 firmware flaw will eventually be drained.
The incident has become one of the largest attacks ever targeting Bitcoin self-custody through cryptographic key generation rather than malware, phishing, or exchange breaches.Security experts say the hack highlights growing operational risks around self-custody as cyber threats evolve, and the incident may accelerate adoption of regulated custodians and spot Bitcoin ETFs.
Anyone holding $BTC on a Coldcard-generated address who has not yet moved their funds is urged to do so immediately using a freshly generated seed on a separate, unaffected wallet.
Sources:CoinDesk: Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 millionDecrypt: Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining WalletsCoinDesk: How Bitcoin cold wallets lost $70 million in an attack that never touched the devices