Coldcard Hit Again: How Some Users Can Stop Pending Transfers
Key Takeaways
- •Galaxy Digital's Alex Thorn reported a likely fourth coordinated wave of attacks targeting Coldcard wallet users on August 3, 2026, involving approximately 388.9 BTC valued at roughly $24.4 million.
- •The analysis identified 218 suspicious transactions across 462 suspected victim addresses, with a sweep rate about 45 times higher than the pre-incident baseline.
- •Some unauthorized transactions remain unconfirmed in Bitcoin's mempool and may be replaceable through the RBF mechanism if affected users act quickly with higher-fee replacement transactions.
- •A portion of the Bitcoin has already moved to second-hop wallets, indicating those original sweeps have confirmed and cannot be reversed through Replace-by-Fee.
- •Thorn advised all Coldcard users to immediately transfer funds to new wallets created with fresh security credentials and to never share seed phrases or private keys with anyone offering recovery assistance.

Alex Thorn, Galaxy Digital's Managing Director and Head of Firmwide Research, reported what he described as a likely fourth organized wave of attacks targeting Coldcard wallet users at approximately 1:00 UTC on August 3, 2026 — just days after the first wave was reviewed. Coldcard, a Bitcoin-only hardware wallet manufactured by Coinkite, is widely used by self-custody holders for its air-gapped signing model, making repeated coordinated sweeps a significant concern for a segment of users who rely on dedicated hardware for key protection.
Thorn's on-chain analysis covered Bitcoin blocks 960,778 through 960,792, spanning roughly two and a half hours of activity that was still ongoing at the time of publication. The cluster contained 218 transactions involving 462 suspected victim addresses and 216 previously unused destination addresses. Together, they moved 388.92748828 BTC. With Bitcoin trading near $62,700 at the time of writing, the total was worth approximately $24.4 million.
The figure represents suspected transfers rather than confirmed, irrecoverable losses. Some transactions were still waiting in Bitcoin's mempool, and the Coldcard attribution was based on Thorn's on-chain analysis rather than a completed investigation by Coinkite or law enforcement.
🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW
THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS
pattern identified: blocks…
— Alex Thorn (@intangiblecoins) August 3, 2026
The Pattern Matched the Earlier Coldcard Incident
Thorn recorded approximately 13.8 suspected sweeps per Bitcoin block, compared with 0.3 per block during a control period before the incident — a rate roughly 45 times higher than normal.
The input history also matched the earlier suspected Coldcard activity. According to Thorn, none of the transaction inputs predated the firmware boundary associated with the vulnerability. In hardware wallet security, a firmware boundary typically marks the point where a software update changed how the device handles private keys or signs transactions, meaning addresses created or used only before that boundary may not share the same exposure.
The destination pattern was similarly consistent. Almost every transaction sent funds to a separate, newly created address, with only one destination receiving two sweeps. Rather than consolidating the Bitcoin immediately into a single collection wallet, the transactions distributed funds across hundreds of fresh addresses, making the cluster less obvious at a glance.
Taken together, the sharp increase in sweeps, the matching input history, and the repeated use of fresh destinations led Thorn to attribute the activity to another wave of Coldcard victims. The analysis did not identify who controlled the receiving addresses or how many individual users were affected.
Some Pending Transactions May Still Be Replaceable
The 388.9 BTC total includes transactions that had already confirmed and others still waiting in the mempool — the holding area where valid Bitcoin transactions remain until a miner includes them in a block.
An unconfirmed transaction may still be replaceable when it signals Replace-by-Fee, commonly known as RBF. Thorn said the confirmed transactions in the cluster had signalled RBF opt-in before entering a block, and similar transactions still waiting for confirmation may use the same setting. RBF has been a standard feature of Bitcoin Core since 2016 and is opted into at the time a transaction is created, meaning not all unconfirmed transactions can be replaced.
Bitcoin's RBF mechanism allows an unconfirmed transaction to be replaced by another transaction spending the same coins with a higher fee. An affected owner who still controls the relevant private keys may therefore be able to redirect the Bitcoin to a secure wallet by issuing a valid replacement with a higher fee than the attacker's transaction.
Recovery is not guaranteed, however. The replacement must satisfy Bitcoin's transaction policies, the attacker may also increase the fee, and the opportunity ends once the unauthorized transaction is confirmed.
Second-Hop Transfers Close the RBF Window
Thorn found that some of the Bitcoin had already moved from the initial destination addresses into second-hop wallets. A first-hop address receives the original sweep; a second hop occurs when the Bitcoin is transferred again to another address.
That movement indicates the original sweep has already confirmed, removing any possibility of replacing it through RBF. Replace-by-Fee can compete with a transaction still in the mempool, but it cannot reverse one already recorded on the blockchain.
The Bitcoin remains traceable on-chain, although further transfers can divide it among additional addresses, combine it with other funds, or move it toward exchanges and other services. Recovery may then depend on identifying those services and obtaining cooperation from their operators or law-enforcement authorities.
What Coldcard Users Should Do Now
Thorn urged users to act quickly: "MOVE YOUR FUNDS OFF COLDCARD DEVICES ASAP AND USE HIGH TX FEES."
Users should first review their transaction history for any outgoing payments they did not authorize. If a suspicious transaction remains unconfirmed and is marked as replaceable, the owner may still be able to issue a higher-fee transaction sending the same Bitcoin to a secure wallet. Anyone unfamiliar with the process should seek urgent assistance from a trusted Bitcoin security professional rather than experimenting with the affected funds.
Any remaining Bitcoin should be transferred to a new wallet created with fresh security credentials. Moving funds to another address generated from the same potentially compromised seed would not remove the underlying risk.
Users should never provide a seed phrase, private key, wallet backup, or PIN to anyone offering recovery assistance. Those secrets are not required to inspect a public transaction or determine whether it remains unconfirmed.
If an unauthorized transaction has already confirmed, users should preserve the transaction ID, wallet records, and relevant device information for tracing, reporting, and any later investigation.
Security warning: Never provide a seed phrase, private key, wallet backup, or PIN to anyone offering recovery assistance. Users facing an unconfirmed unauthorized transaction should seek urgent help from a trusted Bitcoin security professional.
Methodology
The article uses Alex Thorn's August 3, 2026 on-chain analysis covering Bitcoin blocks 960,778 through 960,792. The dollar estimate multiplies 388.92748828 BTC by the stated Bitcoin price of $62,700. The wave attribution represents Thorn's assessment and should not be treated as a final finding from Coinkite, law enforcement, or an independent forensic investigation.