Skip to content
Crypto News Today

Coldcard Wallet Hack: Fourth Wave Pushes Losses to $114M

Illustration showing two Coldcard hardware wallets on either side of a headline reading “Coldcard Wallet Hack Losses Hit $114M as Fourth Theft Wave Emerges,” representing a reported security breach affecting bitcoin wallets.
  • A fourth wave of thefts from Coldcard-generated bitcoin addresses has pushed cumulative losses to roughly 1,816 BTC, near $114 million, since July 30.
  • Unlike the first three waves, Monday’s transactions used bitcoin’s replace-by-fee feature, giving victims who spot their address in the mempool a short window to move funds before the attacker’s transaction confirms.
  • The flaw traces to a March 2021 Coldcard firmware bug that generated seeds predictably; Coinkite has released emergency firmware and is urging affected users to move funds to a freshly generated seed.

Bitcoin wallets built on Coldcard hardware are being drained for a fourth time since Thursday, with researchers now estimating total losses close to $114 million.

A Fourth Wave With a Different Signature

Alex Thorn, head of firmwide research at Galaxy Research, flagged the new wave early Monday after spotting 218 transactions hit 462 addresses at roughly 14 sweeps per block, about 45 times the rate seen before the incident began. He had no direct victim report and chose speed over confirmation to warn holders while transactions were still unconfirmed.

This wave looks different from the first three. The attacker opted into a Bitcoin feature that allows a pending transaction to be overwritten by a later one paying a higher fee. Until a transaction confirms, anyone who spots their own address in the mempool, the queue of unconfirmed transfers, can broadcast a competing transaction with a higher fee and move their coins out first. Thorn urged affected users to check their funds and bid the fee up if targeted.

The pattern also suggests the flaw is limited to single-key Coldcard seeds. None of the four waves have touched multisignature setups, and the destination addresses this round were freshly generated rather than the shared collector wallets that made earlier waves easier to trace. 

What It Means for Wallet Security and the Market

The root cause traces to a Coldcard firmware build from March 2021 that routed seed generation through a predictable software randomizer instead of the device’s hardware one, leaving the resulting keys reproducible offline. 

Coinkite has released corrected firmware for every affected model and says updating alone does not protect existing funds. Anyone who generated a seed on the flawed software needs to move their coins to a wallet built on a new one, since the old keys remain compromised regardless of the firmware version now running on the device.

For the market, the episode adds to a summer already marked by hardware-wallet distrust rather than moving bitcoin’s price on its own. Coldcard-linked losses have climbed in stages since Thursday without triggering the kind of panic selling seen after past custody failures, but each new wave chips away at confidence in cold storage as the default safe option, a dynamic worth watching if it starts nudging smaller holders back toward exchange custody.

Tags: BTC, Hack

Source:

Galaxy Research (Alex Thorn): X post flagging the fourth wave

Coldcard: Bitcoin-Only Hardware Wallet