Home Finance SKN | Suspected Fourth Coldcard Attack Wave Drains 448 Bitcoin as Security Experts Warn Users to Act
Finance

SKN | Suspected Fourth Coldcard Attack Wave Drains 448 Bitcoin as Security Experts Warn Users to Act

Share
Share

Key Points

  • Galaxy Digital researchers have identified a suspected fourth wave of attacks targeting vulnerable Coldcard Bitcoin wallets.
  • The latest incident involved 448.7 Bitcoin moving from 709 potential victim addresses in coordinated transactions.
  • Galaxy’s Alex Thorn said some attack transactions remain unconfirmed, potentially giving affected users a brief opportunity to secure their funds.
  • The attacks follow the discovery of a years-old firmware flaw that reduced the randomness used to generate wallet recovery seeds on certain Coldcard devices.

Researchers are warning that a new wave of coordinated attacks is targeting vulnerable Coldcard Bitcoin hardware wallets, just days after earlier thefts affected thousands of users.

In a post published on Monday, Galaxy Digital Head of Research Alex Thorn identified what appears to be a fourth attack wave, involving approximately 448.7 Bitcoin (BTC) transferred from 709 potential victim addresses.

The latest activity adds to an expanding investigation into one of the largest hardware wallet security incidents in recent years.

Attack Pattern Matches Earlier Incidents

According to Thorn, the transactions closely resemble the behavior observed during previous Coldcard-related attacks.

He reported that the activity averaged 13.8 wallet sweeps per Bitcoin block, roughly 45 times higher than normal transaction patterns observed before the incident.

Rather than consolidating stolen Bitcoin into a single wallet, the attacker appears to be creating a new destination address for each victim, making the movement of funds more difficult to track.

Researchers also observed that some of the stolen Bitcoin has already been transferred into second-hop wallets, indicating efforts to further obscure the assets’ movement.

Some Users May Still Have Time to React

Thorn noted that several suspicious transactions remain unconfirmed in Bitcoin’s mempool, creating a narrow window during which some affected users may still be able to protect their funds.

If users still control the corresponding private keys, they may be able to broadcast a competing transaction with a higher network fee, transferring their Bitcoin to a secure wallet before the attacker’s transaction is confirmed.

However, the opportunity depends on transaction timing and confirmation status, making rapid action essential for any potentially affected users.

Firmware Flaw Linked to Ongoing Investigation

The attacks follow Coinkite’s disclosure of a previously undetected firmware vulnerability affecting certain Coldcard Mk3 devices.

According to the company, the flaw caused some wallet recovery seeds to be generated with lower entropy than intended after changes introduced in 2021 altered the wallet’s random number generation process.

Security researchers believe the reduced randomness may have made certain wallet recovery phrases significantly easier to reproduce, potentially allowing attackers to derive private keys and steal Bitcoin.

Investigations into the precise exploitation method remain ongoing.

Estimated Losses Continue to Rise

The latest attack wave adds to losses already attributed to the Coldcard security incident.

Current estimates suggest that thousands of wallets have been affected, with total stolen Bitcoin now exceeding $90 million in value.

Researchers continue identifying additional compromised wallets while working alongside affected users and law enforcement agencies to trace stolen funds across the Bitcoin blockchain.

Outlook

The suspected fourth wave of Coldcard-related thefts highlights the continuing risks posed by the recently disclosed firmware vulnerability. As investigators uncover additional affected wallets, users of potentially impacted Coldcard devices are being urged to migrate their Bitcoin to newly generated wallets as quickly as possible. The incident is also prompting broader discussion across the cryptocurrency industry about hardware wallet security standards, firmware verification and the importance of robust cryptographic randomness in protecting digital assets.

Comparison, examination, and analysis between investment houses

Leave your details, and an expert from our team will get back to you as soon as possible

    Share

    Don't Miss

    SKN | Crypto Market Cap Reclaims $3 Trillion as Bitcoin and Altcoins Rally on Strong ETF Inflows

    The cryptocurrency market briefly reclaimed the $3 trillion valuation on September 22, 2026, as Bitcoin and major altcoins advanced sharply, supported by strong...

    SKN | Ondo Enables Institutions to Convert Stocks Directly Into Tokenized Shares

    Key Takeaways Ondo Finance has introduced in-kind conversion, allowing approved institutions to exchange existing stocks and ETFs directly for tokenized versions without using...

    Related Articles

    SKN | Bitcoin’s Bear Markets Are Getting Milder as Institutional Capital Reshapes the Cycle

    Key Points: Bitcoin’s latest downturn saw a drawdown of roughly 55% from...

    SKN | Bitcoin Consolidates Near $84K as Crypto Market Strength Broadens

    Key Points: Bitcoin traded near $84,410 after gaining 10.25% over seven days,...

    SKN | XRP Falls 7% After a 16% Weekly Surge: Is the Rally Losing Momentum?

    Key Points: XRP surged 15.8% to $1.66 through September 23 before falling...

    SKN | Could Bitcoin’s $100,000 Breakout Become Its 2008 Oil Moment?

    Key Points: Mike McGlone compares Bitcoin’s first monthly close above $100,000 with...

    Investcoin

    GET A FREE, EXPERT-BACKED
    INVESTMENT COMPARISON TODAY