Top StoriesBearish
78
BTC

Coldcard Wallet Hack Nears $114M, Fourth Sweep Underway

Coldcard wallet users face potential losses of $114 million as hackers launch a fourth sweeping transaction, using replace-by-fee to outpace victims in fund recovery, according to on-chain data. The attack exploits pending transactions, giving users mere minutes to reclaim funds by outbidding attackers with higher fees.

CoinDeskShaurya Malwa

Quick Take

1

Coldcard wallet losses may reach $114 million from an ongoing series of hacks.

2

A fourth sweeping transaction is using replace-by-fee to race against victims.

3

Victims have minutes to outbid attackers by paying higher transaction fees.

Market Impact Analysis

Bearish

Major hardware wallet hack erodes trust and may cause security concerns in the market.

Timeframeshort

Speculation Analysis

Factuality70/100
RumorsVerified
Speculation Trigger60/100
MinimalExtreme FOMO

Key Takeaways

  • Coldcard wallet losses may reach $114 million from an ongoing series of hacks.
  • A fourth sweeping transaction is using replace-by-fee to race against victims.
  • Victims have minutes to outbid attackers by paying higher transaction fees.
Estimated Loss$114MAcross multiple sweeps
Attack WaveFourthSweep underway
MechanismReplace-by-FeeAllows fee outbidding
Response TimeMinutesTo counter with higher fees

What Happened

Coldcard wallet users are under attack as on-chain data reveals a fourth fund-sweeping transaction is in progress, bringing total estimated losses to nearly $114 million. The attackers are exploiting the replace-by-fee feature, which allows them to broadcast transactions with incrementally higher fees, outpacing any attempts by victims to reclaim their funds. This method forces a race where victims must detect the pending transactions in the mempool and quickly submit a conflicting transaction with a higher fee to recover their assets. The window to act is extremely narrow, often just minutes.

The Numbers

The attack has already drained approximately $114 million worth of assets from Coldcard wallets over multiple sweeps. The current fourth sweep continues to target remaining balances. Each fraudulent transaction uses RBF, enabling the attacker to continuously increase fees to stay ahead. The mempool now contains multiple flagged transactions, with victims scrambling to match or exceed the fees to save their funds. The rapid pace leaves little room for error.

Why It Happened

The hack leverages the replace-by-fee protocol, a legitimate Bitcoin feature that allows unconfirmed transactions to be replaced with versions paying higher fees. Attackers are monitoring the mempool for victim transactions and broadcasting competing spends to the same addresses with higher fees, tricking miners into prioritizing their malicious transactions. The specific vulnerability in Coldcard wallet software that enabled the initial breach remains unclear, but the ongoing exploitation highlights the risk of RBF in high-value transactions when wallet security is compromised.

Broader Impact

This incident raises serious questions about hardware wallet security and the broader use of RBF in Bitcoin. While RBF is designed for fee management, its exploitation in large-scale thefts could prompt discussion about default settings in wallet software and whether additional safeguards are needed. The attack may also shake user confidence in self-custody solutions, potentially pushing some toward custodial alternatives despite the trade-offs. Security researchers and wallet developers will likely scrutinize this case to prevent similar exploits.

What to Watch Next

  • On-chain activity: Monitor whether victims successfully recover funds by outbidding the attacker. The next few hours are critical.
  • Coldcard response: Watch for an official statement from Coldcard addressing the breach and any firmware updates or patches.
  • Market sentiment: Track any broader impact on Bitcoin's price and hardware wallet sector as trust may erode temporarily.

Source: CoinDesk

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on CoinDesk
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

Top StoriesBearish
84

Coldcard Exploit Spurs $114M in Thefts, Small BTC Holders Flee

A Coldcard firmware flaw since 2021 has allowed attackers to steal Bitcoin, with losses nearing $114M. On July 31, small holders moved 39,600 BTC—the most since FTX's collapse—as active addresses spiked, though price held steady, signaling moves to secure rather than sell.

BTC
90% confidence
Aug 3, 2026, 10:15 AM UTC · Decrypt
Coldcard Wallet Hack Nears $114M, Fourth Sweep | Bytewit