Coldcard Wallet Drains Reach $114 Million as Fourth Wave of Sweeps Targets Vulnerable Seeds
Key Takeaways
- •The cumulative losses from the Coldcard wallet exploit have reached approximately 1,816 BTC, or roughly $114 million, across more than 5,200 addresses since attacks began on July 30.
- •The root cause is a March 2021 firmware build that used a predictable software fallback for seed generation instead of the device's dedicated hardware random number generator, making private keys reconstructable offline.
- •The fourth attack wave differs from prior waves by using Bitcoin's replace-by-fee feature, giving affected owners a brief window to outbid the attacker and relocate funds before confirmation.
- •Multisignature wallet configurations remained unaffected across all four waves because they require authorization from multiple independent devices, providing a structural safeguard absent in single-key setups.
- •Data from CryptoQuant indicates smaller holders are reversing the post-FTX trend by transferring Bitcoin back onto centralized exchanges rather than maintaining self-custody.

A fourth wave of coordinated sweeps targeting Coldcard-generated Bitcoin wallets began early Monday and continued for hours, according to Galaxy Research, pushing the cumulative losses from the ongoing exploit to approximately 1,816 BTC — roughly $114 million — across more than 5,200 addresses.
Combined with three prior waves dating back to 30 July, the attacks have drained funds at a pace that has repeatedly outpaced earlier estimates. The fourth wave marks the latest in a series of sweeps spanning five consecutive days.
The Vulnerability
The root cause remains unchanged from the first wave. A March 2021 firmware build on certain Coldcard devices, manufactured by Canadian company Coinkite, generated wallet seeds using a predictable software fallback rather than the device's dedicated hardware random number generator. As a result, private keys that owners believed to be cryptographically secure were reconstructable offline by anyone able to work through the possible combinations.
Coldcard is marketed as an air-gapped hardware wallet, meaning it is designed to operate without ever connecting directly to a computer or network. This positioning has made it a popular choice among Bitcoin users who prioritize self-custody and minimize third-party trust. The vulnerability undermined that core promise not through any network exposure, but at the moment of seed creation inside the device itself.
No phishing, malware, or user error was involved. The affected coins had been sitting dormant in wallets that were compromised from the moment they were created, with no outward indication that anything was wrong.
Fourth Wave Uses Replace-by-Fee
Unlike the first three waves, the current batch of transactions employs Bitcoin's replace-by-fee feature, which allows a pending transaction to be overwritten by a subsequent one offering a higher network fee. Until a transaction is confirmed on the blockchain, any owner who identifies their own address in the mempool — the queue of unconfirmed transactions — has a narrow window, measured in minutes, to outbid the attacker and relocate their funds first.
Alex Thorn, Galaxy's head of firmwide research, flagged the active wave and has been tracking the pattern in near real time. He acknowledged that his assessment of the fourth wave is based on judgment rather than direct confirmation. Thorn stated he has no victim report specific to wave four and published his findings on pattern matching alone, opting to alert the public while transactions remained unconfirmed rather than waiting for certainty.
Thorn's analysis represents his interpretation of on-chain behavior, not a confirmed theft report. The earlier three waves, however, have been independently corroborated.
On-Chain Data Shows Sharp Spike
The figures behind wave four are notable. Blocks 960,778 through 960,792 recorded roughly 14 sweeps per block, compared with a pre-incident baseline of approximately 0.3 — a 45-fold increase over normal activity. Two hundred and eighteen transactions targeted 462 victim addresses.
In a departure from earlier waves, funds are being routed to fresh, previously unused addresses rather than the shared collector wallets that made the first two sweeps comparatively easy to trace. The shift suggests the attacker has adapted to heightened scrutiny.
None of the four waves have affected multisignature setups, which is consistent with Coinkite's explanation that the flaw is confined to single-key seed generation. Multisig configurations require multiple independent devices to authorize spending, meaning a compromised seed from a single device alone cannot move funds — a structural safeguard that single-key users did not benefit from. Six destination addresses with years of prior transaction history were excluded from the pattern, on the reasoning that a genuinely new attacker address would not have an existing history.
Impact on Long-Term Holders
The confirmed waves reveal that the average stolen coin had sat untouched for 3.18 years. The victims were predominantly long-term holders who followed widely recommended self-custody practices: purchasing reputable hardware, generating seeds offline, and keeping devices disconnected from the internet.
Canadian coach Jonathan Goodman lost 18.25 BTC within a seven-minute window, despite storing his keys in a bank safety deposit box that had never been connected to a network. "Perhaps the hardest part about this is that I did everything right," he said. The failure was embedded in the device before he purchased it.
Coinkite's Response
Coinkite CEO Rodolfo Novak has publicly apologized and released emergency patches, while noting that the company has not confirmed the firmware bug as the cause of any specific reported theft. A software patch cannot remediate a seed that has already been generated.
Coinkite's own documentation identifies 50 independent dice rolls for entropy, a BIP-39 passphrase, or multisignature configurations as the precautions that would have prevented exploitation. BIP-39 pass phrases function as an additional secret layered on top of the recovery phrase, producing a completely different set of keys if applied. These measures were presented in documentation rather than promoted as essential requirements for customers.
Broader Industry Reactions
Changpeng Zhao, founder of Binance — the exchange that self-custody was originally designed to bypass — stated that "nothing is 100% safe" and urged holders to distribute funds across multiple wallets. The advice is consistent with standard risk management principles, though the source has drawn scrutiny given Binance's position as a centralized exchange.
Data from CryptoQuant indicates a reversal of the trend observed after FTX's collapse: rather than moving Bitcoin from exchanges into self-custody, smaller holders are transferring funds back onto platforms including Binance, Kraken, and OKX. Five years ago, that flow moved in the opposite direction.
Recommended Actions
For Coldcard users, the practical guidance is to determine whether their wallet seed predates the firmware fix, migrate assets to a wallet generated on current firmware, and — if their address appears unconfirmed in the mempool — immediately increase the transaction fee to attempt moving funds ahead of the attacker.
Related coverage: