RBF

Bitcoin
2026-08-13 09:48:48

Faulty RBF script causes user to burn 1.6 BTC in fees, with entire input collected by miners

A Bitcoin user accidentally paid 1.60 BTC, worth about $102,800, in network fees after an automated replace-by-fee, or RBF, script malfunctioned, according to BlockBeats. The transaction did not send any BTC to the intended recipient. On-chain data shows it had a single input totaling 160,343,885 satoshis and an output value of zero, meaning the full amount was absorbed as miner fees. The transaction was included in Bitcoin block 962142 on Aug. 12. The reported issue stemmed from an automation script that raised the RBF fee once per second without a reasonable fee cap, allowing the fee to keep increasing until it consumed the entire input. SpiderPool mined the block, and the transaction accounted for 88% of the block’s roughly 1.82 BTC in total fees. The case highlights how misconfigured fee-bumping tools can produce extreme outcomes on-chain within a short period.

120
Faulty RBF script causes user to burn 1.6 BTC in fees, with entire input collected by miners
Bitcoin
2026-08-13 09:45:46

Bitcoin user burns 1.6 BTC in fees after RBF script spirals out of control

A Bitcoin user paid 1.6 BTC in transaction fees in block 962,142 even though the actual transfer amount was zero, according to BeInCrypto, in a case tied to an automated script using Replace-by-Fee, or RBF. The report said the script kept raising the fee bid every second, eventually draining the wallet’s full balance. SpiderPool mined the block and collected the unexpected payout. The fee alone accounted for about 88% of the block’s total fees, which were reported at roughly 1.82 BTC. The incident points to how automated transaction management can produce outsized losses when fee logic runs without effective limits, especially in setups that repeatedly rebroadcast transactions under RBF rules.

140
Bitcoin user burns 1.6 BTC in fees after RBF script spirals out of control
Bitcoin
2026-08-13 09:46:54

Four Bitcoin transactions burned 1.7715 BTC in fees, accounting for 97.4% of one block’s fee revenue

Bitcoin block 962,142, confirmed on the evening of Aug. 12, contained four transactions from the same address that turned their entire inputs into miner fees. Together, the four transactions paid 177,153,578 satoshis, or 1.7715 BTC, worth about $113,700 at the time, according to the source material. The block included 4,700 transactions in total and collected 1.8189 BTC in fees, which means those four transfers alone made up 97.4% of the block’s fee income. The block was mined by SpiderPool. Each of the four transactions used the same structure: one input and one zero-value OP_RETURN output, leaving no recipient and no change output. In Bitcoin, fees are defined as the difference between total inputs and total outputs, so the entire input value was effectively handed to the miner. The source also said the highest fee rate among the four reached 1,724,128 sat/vB, compared with a block median of 3 sat/vB. The report added that a prior consolidation transaction in the same block had merged scattered UTXOs from 12 addresses into a 1.6034 BTC amount with a normal fee of 858 satoshis, before the subsequent transactions went wrong.

210
Four Bitcoin transactions burned 1.7715 BTC in fees, accounting for 97.4% of one block’s fee revenue
Bitcoin
2026-08-09 18:50:38

$0.65 Bitcoin Transfer Pays $6,514 in Fees, 35% of Next Block's Available Fees

Bitcoin News reports that a single Bitcoin transaction has contributed 9.99 million satoshis — about $6,514 — in fees to the next candidate BIP-110 block. The transfer moved only 1,000 satoshis, worth $0.65, while paying 9.999 million satoshis in fees, a rate of 90,081 sat/vB. That is roughly 35% of the current block's available fees, which total 0.29 BTC, or $18,573. The transaction has replace-by-fee (RBF) enabled, meaning it could be replaced before confirmation. Odaily Planet Daily reported the finding.

530
$0.65 Bitcoin Transfer Pays $6,514 in Fees, 35% of Next Block's Available Fees
Coldcard
2026-08-05 11:34:27

Coldcard RNG flaw tied to four suspected attack waves as scrutiny grows over Bitcoin self-custody risks

A years-old randomness flaw in Coldcard hardware wallet firmware has come under intense scrutiny after several waves of suspicious Bitcoin sweeps were linked by researchers to seeds created under affected software versions. Investigations by Block and Coinkite traced the issue to a 2021 code migration that routed seed generation through a software pseudorandom number generator instead of the intended hardware RNG on some firmware paths, reducing the effective search space of wallet seeds below the design target. Galaxy Research said three suspected attack waves it identified covered 4,585 addresses and 1,367.05 BTC, and on Aug. 3 its researchers flagged a fourth wave that was later updated to about 448.7 BTC across 709 potential victim addresses. Those figures come from on-chain pattern analysis and are not a wallet-by-wallet confirmation of Coldcard victims or final losses. The incident has also reopened debate over custody models. Researchers and market observers pointed to higher address activity, movements from older UTXOs, and inflows to centralized venues after the disclosure, while cautioning that on-chain data alone cannot prove those moves were caused by the Coldcard bug. Coinkite has said users with affected seeds need to generate a new seed in patched firmware or another trusted environment and move funds, because updating firmware alone does not restore the missing entropy in an already created mnemonic.

640
Coldcard RNG flaw tied to four suspected attack waves as scrutiny grows over Bitcoin self-custody risks
Coldcard
2026-08-03 11:21:11

Coldcard flaw linked to 1,755 BTC theft as wallet trust comes under pressure

Coldcard’s hardware wallet security crisis has shaken confidence in Bitcoin self-custody after a flaw tied to its March 2021 v4.0.1 firmware update was linked to the theft of 1,755.95 BTC, worth more than $110 million at market prices. The issue stemmed from the use of a pseudo-random number generator instead of a true hardware random number generator during private-key creation, leaving affected wallets exposed to brute-force reconstruction for years. According to Galaxy Research, attackers emptied 1,196 victim addresses in just 41 minutes during the first two waves and moved more than $70 million before Coldcard issued its warning, with the main transfers completed about 30 hours earlier. In a later wave, the attacker used Replace-By-Fee transactions at a pace of as many as 13.8 transfers per block to push transactions through quickly. The fallout spread across the Bitcoin network. CryptoQuant said daily active addresses jumped from 645,000 on July 30 to nearly 1 million on July 31, while transfers below 1 BTC reached the highest level since November 2022, close to the spike seen after FTX filed for bankruptcy. The case also highlighted AI’s dual role in crypto security: attackers were described as using AI at scale, while community developers used Claude Code, Zhipu GLM 5.2 and Kimi K3 to identify and verify the flaw, with one scan reportedly taking just eight minutes.

520
Coldcard flaw linked to 1,755 BTC theft as wallet trust comes under pressure
Coldcard
2026-08-03 08:45:00

Coldcard flaw sparks fresh doubts over Bitcoin self-custody as $110 million in BTC is drained

A long-hidden flaw in Coldcard firmware has triggered one of the most jarring security shocks for Bitcoin self-custody users in recent years. According to PANews, 1,755.95 BTC, worth more than $110 million at market prices, was quietly drained from thousands of addresses on July 30, with most of the funds moved roughly 30 hours before an official warning was issued. The issue traces back to Coldcard’s v4.0.1 firmware released in March 2021, when the wallet reportedly used a pseudo-random number generator instead of a true hardware random source during private key generation. Galaxy Research said the first two waves of attacks emptied 1,196 victim addresses in just 41 minutes and moved more than $70 million before users were broadly alerted. CryptoQuant data showed a sharp jump in on-chain activity after the incident, with Bitcoin active addresses rising from 645,000 on July 30 to nearly 1 million on July 31, while sub-1 BTC transfers climbed to their highest level since November 2022. The episode has pushed market participants to reassess concentration risk in single-wallet setups and renewed discussion around multisig, MPC, social recovery wallets, exchange custody, and spot Bitcoin ETFs as alternatives or complements to pure hardware-wallet storage.

530
Coldcard flaw sparks fresh doubts over Bitcoin self-custody as $110 million in BTC is drained
Coldcard
2026-08-03 09:18:00

Coldcard wallet exploit may have entered a fourth sweep, with losses nearing $114 million

A security incident tied to Coldcard hardware wallets appears to be widening, with total losses potentially nearing $114 million, according to CoinDesk and on-chain analysis cited by Galaxy Research head Alex Thorn. Thorn said a new Bitcoin sweep attack targeting Coldcard-derived addresses appears to be underway and that the latest transactions are using Replace-by-Fee, or RBF. That gives affected users a limited chance to outbid an attacker and redirect funds to a safe address if they spot their transaction in the mempool before confirmation. The attack was first observed on July 30. The first wave moved about 1,083 BTC from 1,196 addresses in 41 minutes. Two later waves pushed confirmed losses to roughly 1,367 BTC across 4,585 addresses. If the fourth wave estimate holds, around 1,816 BTC has been moved since July 30, affecting more than 5,200 addresses. Researchers believe the issue traces back to a March 2021 Coldcard firmware version that used a predictable software random number generator during seed creation instead of the chip’s hardware entropy source. Manufacturer Coinkite has released an emergency firmware update and advised users to move assets to wallets created from entirely new seeds. Current research indicates the incident mainly affects single-signature wallets, with no multisig impact identified so far.

610
Coldcard wallet exploit may have entered a fourth sweep, with losses nearing $114 million