- With losses totaling 1,816 BTC (almost $114 million) over more than 5,200 Bitcoin wallet addresses since July 30, the fourth wave of the coldcard wallet attack has begun.
- Alex Thorn of Galaxy Digital cautioned that Replace-by-Fee (RBF) can still be used to override some unconfirmed Bitcoin transactions, providing impacted consumers an opportunity to protect their money.
- The attack takes advantage of a 2021 Coldcard firmware flaw that used a weaker random number generator to provide predictable wallet seed phrases.
Early on Monday, a fourth wave of sweeps against Bitcoin addresses created by the Coldcard cold wallet started, and hours later, it was still active. However, this time, the transactions can be overridden while they remain unconfirmed, according to researchers.
🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW
THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS
pattern identified:
blocks…— Alex Thorn (@intangiblecoins) August 3, 2026
Alex Thorn, Head of Firmwide Research at Galaxy Digital, issued a warning about an impending fourth planned Coldcard attack in a post on X. He pointed out that a number of dubious transactions were still pending in the Bitcoin mempool, which could allow some users to swap out their transactions for higher-fee versions (RBF) and transfer their money before the attackers were successful.
In order to make it more challenging for investigators to follow the flow of money, the attackers also modified their approach by distributing stolen Bitcoin to hundreds of newly established wallet addresses rather than a small number of central collection wallets.
Coldcard Hack Hits Thousands Of Bitcoin Wallets Before Fourth Wave
Galaxy Research had already discovered three distinct waves of wallet sweeps prior to the most recent attack. In just the third wave, 1,912 addresses lost 208 BTC, with each victim losing little more than 0.1 BTC on average.
In a sweep that seized 1,083 bitcoin from 1,196 addresses in 41 minutes, the attack began on July 30. Over the weekend, two further waves resulted in observed losses of 1,367 bitcoin over 4,585 addresses.
Firmware Bug Created A Security Risk
A firmware flaw that was discovered in March 2021 during revisions to Coldcard’s wallet software is connected to the assaults. Affected firmware erroneously relied on a weaker MicroPython pseudo-random number generator rather than the device’s specified True Random Number Generator (TRNG) to generate wallet seed phrases.
Attackers could replicate vulnerable private keys offline without requiring physical access to the devices because the number of potential wallet seeds decreased significantly.
Coldcard wallet manufacturer Coinkite ceased selling impacted devices and destroyed any remaining stock that contained the vulnerable firmware after the revelation. Additionally, the corporation has recommended that users maintain their impacted gadgets because they can be crucial in the event that stolen money is found through further legal investigations.
Fourth Coldcard Attack Wave Gives Some Bitcoin Users A Chance to Recover Funds
Users were instructed by Thorn to check their money, remove anything from a compromised device, and raise the charge.
With 218 transactions hitting 462 victim addresses at a rate of nearly 14 sweeps per block compared to 0.3 in a pre-incident control window,roughly 45 times normal,the pattern covered blocks 960,778 to 960,792.
Instead of the shared collectors that made the first two waves simple to map, each spent coin that arrived after the Coldcard firmware boundary and the destinations were new addresses with no prior history, one per victim.
You need to login in order to Like









Leave a comment