Coldcard wallets face fourth suspected attack wave, ~388.9 BTC moved
Security & Exploits ยท
Galaxy Research says a new wave of coordinated transactions targeting Coldcard-generated addresses has drained roughly 388.9 BTC, extending a pattern first flagged in earlier incidents this year.
Alex Thorn, Head of Research at Galaxy Research, said the fourth wave may be actively targeting Coldcard users, according to wublockchain.xyz. Between blocks 960,778 and 960,792, 218 transactions touched 462 victim addresses and 216 fresh destination addresses, moving roughly 388.9 BTC in total. Activity during the window ran about 45 times higher than the pre-incident baseline, and some of the moved funds have already been swept to second-hop addresses, complicating efforts to trace or recover them.
Similar transactions are still sitting unconfirmed in the mempool, and confirmed transactions in the wave show replace-by-fee opt-in, meaning attackers can rebroadcast with higher fees to push transactions through faster. Galaxy Research's guidance is for affected users to move funds off Coldcard devices immediately and to use higher fees where possible, noting that RBF may offer some eligible victims a way to intervene before funds are lost. The scale of the current wave adds to three previously identified attack waves that Galaxy Research attributed to Coldcard-generated addresses, which together affected 4,585 addresses and drained 1,367.05 BTC, valued at approximately $88.6 million.
Coldcard has responded by halting shipments and destroying all remaining devices running the vulnerable firmware, according to wublockchain.xyz. The company said its Satscard, Opendime, and Tapsigner products are unaffected by the issue. A patched firmware version is available and protects newly generated seeds, but the fix does not retroactively secure existing wallets โ users who generated a seed on the vulnerable firmware must create an entirely new seed and migrate their funds rather than simply updating the device.
The incident has drawn coverage from multiple outlets, including a report from cryptopotato.com framing the fourth wave as putting additional bitcoin at risk, alongside further reporting from decrypt.co.
What remains unclear is how many of the 462 victim addresses in this latest wave belong to users who already migrated off vulnerable firmware versus those still exposed, and whether the pending mempool transactions will be confirmed before affected users can act. It is also not yet established whether the entity or entities behind all four waves are the same, or how funds swept to second-hop addresses will ultimately be tracked.