BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Coldcard losses near $114M as fourth attack wave hits

A fourth wave of coordinated sweeps against Coldcard-generated Bitcoin addresses struck on Monday, with Galaxy Research head @intangiblecoins flagging roughly 449 $BTC pulled from 709 likely

AnonymousCryptoCompass newsroom
August 3, 2026
3 min read
NEWS
Coldcard losses near $114M as fourth attack wave hits
CryptoCompass editorial visual for bitcoin coverage.

A fourth wave of coordinated sweeps against Coldcard-generated Bitcoin addresses struck on Monday, with Galaxy Research head @intangiblecoins flagging roughly 449 $BTC pulled from 709 likely victim addresses. Researchers now estimate the attacker has moved about 1,816 $BTC, or roughly $114 million, from more than 5,200 addresses since July 30.

How the Attack Unfolded

The attack began on July 30 in a sweep that took 1,083 $BTC from 1,196 addresses in just 41 minutes. Two further waves over the weekend brought observed losses to 1,367 $BTC across 4,585 addresses. The fourth wave extended that damage further, with @intangiblecoinsnoting the activity averaged 13.8 sweeps per block, around 45 times the rate observed in a pre-incident control window.

The root cause is a firmware flaw introduced years ago. The vulnerability, introduced in Coldcard firmware 4.0.0 in March 2021, caused devices to skip their hardware randomness generator and fall back to predictable software-based key generation seeded by nonsecret chip data. That made supposedly unguessable seed phrases computationally reproducible, allowing attackers to reconstruct private keys without ever touching the devices.

The pattern suggests the flaw affects single-key Coldcard seeds and not multisignature setups.Drained holdings had sat dormant for an average of 3.18 years, suggesting most victims were long-term holders rather than institutions.

A Narrow Window for Victims

The fourth wave carries an unusual, if time-sensitive, lifeline. Unlike earlier waves, the latest transactions appear to use Bitcoin's replace-by-fee feature, meaning victims who spot their coins in the mempool may still be able to outbid the attacker and move their funds first.Alex Thorn, head of firmwide research at Galaxy Research, flagged the active wave and said the attackers opted into replace-by-fee, a Bitcoin feature that lets a pending transaction be overwritten by a later one paying a higher fee. Until a transaction confirms, a victim who finds their address in the mempool can pay more and move the coins out first.

Coldcard manufacturer Coinkite released emergency firmware for every affected model and told users who had generated a seed on the flawed software to move funds to a wallet address made with a fresh one.Coinkite has warned users who created seeds on Mk3 devices running firmware 4.0.1 or later, while stressing that Mk4, Q and Mk5 appear unaffected so far. Critically, fixed firmware protects newly generated seeds, but existing vulnerable seeds still require complete wallet migration.

Galaxy said it has flagged roughly 600 suspected attacker addresses to federal investigators, compliance firms and cross-industry cyber investigators. Anyone holding $BTC on a potentially affected Coldcard device is urged to check the mempool immediately and migrate funds using high fees.

Sources:CoinDesk: Bitcoin cold-wallet losses may near $114 million as possible fourth sweep emergesCrypto.news: Coldcard losses rise as fourth attack wave sweeps 448 BTCThe Hacker News: Coldcard Hardware Wallet Flaw Linked to Bitcoin Theft