Suspected Fourth Wave of Coldcard Attacks Moves Over 448 Bitcoin, Galaxy Reports
Key Takeaways
- •Researchers have identified a fourth wave of coordinated thefts targeting Coldcard Bitcoin hardware wallets since the attacks began last Thursday.
- •The latest wave involves approximately 709 potential victim addresses and 448.7 Bitcoin, with transaction rates running 45 times higher than pre-incident levels.
- •The underlying vulnerability is a firmware flaw that generated wallet recovery seeds with insufficient entropy, making them predictable and vulnerable to brute-force attacks.
- •Cumulative losses across all attack waves are estimated to exceed $90 million, with thousands of wallets impacted.
- •Users who still control their private keys may be able to recover funds by broadcasting a higher-fee conflicting transaction before attackers complete their transfers.

Update (Aug. 3 at 4:19 am UTC): This article has been updated with the latest estimated number of affected addresses and Bitcoin from Galaxy's Alex Thorn.
A new wave of coordinated thefts targeting Coldcard Bitcoin hardware wallets has been identified, marking what researchers believe is the fourth such attack wave since the initial incidents began last Thursday.
In a post on X, Galaxy research head Alex Thorn flagged hundreds of transactions impacting 709 potential victim addresses and moving a combined 448.7 Bitcoin (BTC). Thorn reported that the activity averaged 13.8 sweeps per block — roughly 45 times the rate recorded during a pre-incident control window. Most transfers generated a fresh destination address for each individual victim rather than routing funds to a central collection wallet, a pattern consistent with earlier waves.
Thorn also indicated that some stolen funds had already been moved onward to second-hop addresses.
"These are LIKELY Coldcard victims — they match the shape of coldcard vulnerable utxos and the elevated transaction pattern gives me high confidence they are another wave of attacks," Thorn wrote.
The researcher noted that additional transactions matching the same pattern were visible in the mempool awaiting confirmation.
Affected users who retain control of their private keys may still have an opportunity to broadcast a conflicting transaction with a higher fee, potentially relocating their funds to a secure wallet before an attacker's transfer is confirmed on-chain. The use of per-victim destination addresses and rapid onward movement to second-hop addresses suggests an effort to complicate blockchain tracing, a technique that aligns with observed laundering strategies in prior large-scale cryptocurrency thefts.
The ongoing thefts trace back to a previously undetected Coldcard firmware flaw. The vulnerability caused affected hardware wallet devices to generate wallet recovery seeds with lower entropy than intended, making those seeds far more predictable and susceptible to brute-force exploitation. Coldcard devices are hardware wallets designed to store Bitcoin private keys offline, and the seed-generation defect undermined that security model at a foundational level. Hardware wallets are widely recommended as a best practice for self-custody of cryptocurrency assets precisely because they isolate private keys from internet-connected devices, making a flaw in random seed generation a particularly severe class of vulnerability.
Current estimates indicate that thousands of wallets have been impacted, with cumulative losses now exceeding $90 million in Bitcoin.
Related: Coldcard Bitcoin loss estimate rises to $70M after Galaxy analysis