A security incident linked to Coldcard hardware wallets is still expanding. According to CoinDesk, a suspected fourth round of fund movements has appeared, pushing the potential loss total close to $114 million.
Alex Thorn, head of research at Galaxy Research, said a new Bitcoin sweep attack targeting Coldcard wallet addresses appears to be in progress. The latest transactions are using Replace-by-Fee, or RBF. That means affected users may still have a narrow window to override an attacker’s transaction by paying a higher fee and sending the funds to a safe address, if they detect their address in the Bitcoin mempool before confirmation.
The incident was first seen on July 30. In the first wave, about 1,083 BTC was moved from 1,196 addresses within 41 minutes. Two later waves pushed confirmed losses to roughly 1,367 BTC across 4,585 addresses. If the fourth-wave count is accurate, about 1,816 BTC has been moved since July 30, worth roughly $114 million at current prices, across more than 5,200 addresses.
Researchers believe the vulnerability stems from a Coldcard firmware version released in March 2021. In that version, wallet seeds were generated with a predictable software random number generator instead of the chip’s hardware entropy source, making it possible for some private keys to be derived offline.
Coinkite, the maker of Coldcard, has issued an emergency firmware update and advised affected users to move their assets to wallets created from entirely new seeds.
Thorn said there have been no direct victim reports so far. His assessment is based mainly on on-chain transaction patterns. Because some of the attack transactions are still unconfirmed, he chose to disclose the situation early to alert users and give them time to act.
Security research indicates the attack mainly affects single-signature wallets. No impact on multisignature wallets has been identified so far. Users who may be affected should check wallet addresses generated by Coldcard devices and move any remaining assets as soon as possible.

