Coldcard wallet exploit may have entered a fourth sweep, with losses nearing $114 million

Coldcard wallet exploit may have entered a fourth sweep, with losses nearing $114 million

N
News Editor
2026-08-03 09:18:00
A security incident tied to Coldcard hardware wallets appears to be widening, with total losses potentially nearing $114 million, according to CoinDesk and on-chain analysis cited by Galaxy Research head Alex Thorn. Thorn said a new Bitcoin sweep attack targeting Coldcard-derived addresses appears to be underway and that the latest transactions are using Replace-by-Fee, or RBF. That gives affected users a limited chance to outbid an attacker and redirect funds to a safe address if they spot their transaction in the mempool before confirmation. The attack was first observed on July 30. The first wave moved about 1,083 BTC from 1,196 addresses in 41 minutes. Two later waves pushed confirmed losses to roughly 1,367 BTC across 4,585 addresses. If the fourth wave estimate holds, around 1,816 BTC has been moved since July 30, affecting more than 5,200 addresses. Researchers believe the issue traces back to a March 2021 Coldcard firmware version that used a predictable software random number generator during seed creation instead of the chip’s hardware entropy source. Manufacturer Coinkite has released an emergency firmware update and advised users to move assets to wallets created from entirely new seeds. Current research indicates the incident mainly affects single-signature wallets, with no multisig impact identified so far.

A security incident linked to Coldcard hardware wallets is still expanding. According to CoinDesk, a suspected fourth round of fund movements has appeared, pushing the potential loss total close to $114 million.

Alex Thorn, head of research at Galaxy Research, said a new Bitcoin sweep attack targeting Coldcard wallet addresses appears to be in progress. The latest transactions are using Replace-by-Fee, or RBF. That means affected users may still have a narrow window to override an attacker’s transaction by paying a higher fee and sending the funds to a safe address, if they detect their address in the Bitcoin mempool before confirmation.

The incident was first seen on July 30. In the first wave, about 1,083 BTC was moved from 1,196 addresses within 41 minutes. Two later waves pushed confirmed losses to roughly 1,367 BTC across 4,585 addresses. If the fourth-wave count is accurate, about 1,816 BTC has been moved since July 30, worth roughly $114 million at current prices, across more than 5,200 addresses.

Researchers believe the vulnerability stems from a Coldcard firmware version released in March 2021. In that version, wallet seeds were generated with a predictable software random number generator instead of the chip’s hardware entropy source, making it possible for some private keys to be derived offline.

Coinkite, the maker of Coldcard, has issued an emergency firmware update and advised affected users to move their assets to wallets created from entirely new seeds.

Thorn said there have been no direct victim reports so far. His assessment is based mainly on on-chain transaction patterns. Because some of the attack transactions are still unconfirmed, he chose to disclose the situation early to alert users and give them time to act.

Security research indicates the attack mainly affects single-signature wallets. No impact on multisignature wallets has been identified so far. Users who may be affected should check wallet addresses generated by Coldcard devices and move any remaining assets as soon as possible.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
610

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.