đź“°
Top StoriesBearish
78
BTC

Coldcard Wave Four: $15M Bitcoin Swept in Ongoing Attack

A new wave of Coldcard wallet thefts has drained 389 Bitcoin from 462 addresses, exploiting a firmware flaw. Galaxy's Alex Thorn warns of ongoing attacks with transactions still pending in the mempool, urging users to counter-sweep their funds.

CointelegraphCointelegraph by Felix Ng

Quick Take

1

Fourth attack wave hits Coldcard users, sweeping 389 BTC to fresh addresses.

2

On-chain analysis shows 13.8 sweeps per block, confirming coordinated thefts.

3

Firmware entropy flaw exposed; total losses now estimated at $90M across 1,100 wallets.

4

Affected users can broadcast higher-fee transactions to rescue funds before confirmation.

Market Impact Analysis

Bearish

The theft highlights security vulnerabilities in hardware wallets, which could undermine confidence in self-custody solutions and trigger cautious sentiment.

Timeframeshort

Speculation Analysis

Factuality85/100
RumorsVerified
Speculation Trigger50/100
MinimalExtreme FOMO

Key Takeaways

  • A fresh wave of coordinated attacks has swept 389 BTC from Coldcard hardware wallets, exploiting a firmware entropy flaw.
  • On-chain data confirms 13.8 sweeps per block—a 45-fold surge over normal activity—signaling an automated, ongoing theft operation.
  • Total losses have climbed to $90 million across more than 1,100 wallets, making this one of the largest hardware wallet vulnerabilities ever recorded.
  • Victims still controlling their keys can attempt to counter-spend with a higher fee to intercept unconfirmed transactions.
Stolen This Wave389 BTCfrom 462 addresses
Sweeps per Block13.845x pre-incident rate
Victim Impact1,100+ wallets$90M total stolen

What Happened

A fourth wave of thefts targeting Coldcard hardware wallets has drained 389 Bitcoin—worth approximately $15 million—from 462 victim addresses. Galaxy research head Alex Thorn flagged 218 transactions in a matter of hours, each moving funds to fresh destination addresses rather than a central collection point. Some sums have already been shuttled to second-hop wallets, complicating traceability. Similar unconfirmed transactions remain in the mempool, indicating the attack is not yet contained. Affected users may still have a narrow window to outrace the thief by broadcasting conflicting transactions with higher fees.

The Numbers

The attack’s velocity is unmistakable. Thorn observed an average of 13.8 sweep transactions per block—45 times the baseline rate seen before the incident. Since the firmware flaw first came to light, over 1,100 wallets have been compromised, with cumulative losses reaching $90 million. The latest wave alone moved 389 BTC, split across hundreds of newly created outputs. Each victim’s UTXO appears to be handled individually, suggesting a highly automated script tailored to the vulnerable key generation pattern.

Why It Happened

The root cause is a previously undetected firmware bug in certain Coldcard devices that generated wallet seeds with critically low entropy. Instead of producing truly random private keys, the flawed firmware used predictable inputs, making it feasible for attackers to derive the same seeds and sweep funds. Once the vulnerability pattern was identified, coordinated sweeps began, with this fourth wave demonstrating that the exploit window remains open. The incident underscores the existential importance of verifiable randomness in self-custody solutions.

Broader Impact

The theft erodes trust in hardware wallets, long considered the gold standard for securing Bitcoin. With Coldcard popular among security-conscious users, the revelation may prompt a broader audit of firmware across competing devices. It also reignites the debate over multisig, passphrases, and other defense layers that could have mitigated the damage. For now, the incident serves as a stark reminder that even dedicated hardware is only as secure as its least audited component.

What to Watch Next

  • Mempool activity: Monitor for further unconfirmed sweep transactions. A spike could indicate the attack is accelerating.
  • Counter-sweep success rate: Watch whether victims successfully rescue their funds via high-fee replacement transactions.
  • Coldcard response: Look for updated firmware patches and a formal post-mortem explaining the entropy failure and remediation steps.

Source: Cointelegraph

This article is for informational purposes only and does not constitute financial advice.

SourceRead the full article on Cointelegraph
Read full article

Always late to trends?

Join for the latest news, insights & more.

Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.

© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.

Read Next

Most Read

⚡
Top StoriesBearish
82

Coldcard 5-Year Seed Flaw Drains $90M, Exposing Testing Gap

A five-year bug in Coldcard hardware wallets routed seed generation to a weak RNG, enabling theft of $90M in BTC. Kraken's security chief demands independent testing mandates, akin to payments and government standards, to close the verification gap in digital asset self-custody.

BTC
90% confidence
Aug 3, 2026, 4:09 AM UTC · Cointelegraph
Coldcard Theft Wave 4: 389 BTC Swept | Bytewit