- The estimated losses from the Coldcard attack have climbed to $90M, with 1,367+ BTC drained from over 4,500 wallets.
- The active fourth wave has impacted 462 wallets, shifting 388.92 BTC across 218 transactions into 216 newly created addresses.
What started as a warning has become one of the most serious hardware wallet security incidents in Bitcoin’s history. Over the past three days, Coldcard devices running vulnerable firmware have been drained by attackers who discovered a critical flaw.
The seed phrases generated by affected devices had lower entropy than intended, making them predictable and exploitable. The damage had reached an estimated $90 million stolen from over 4,500 wallets, with over 1,367 BTC drained across multiple coordinated waves of attacks.
The Fourth Wave Is Still Active
Alex Thorn, Head of Research at Galaxy Research, flagged a likely fourth wave. The pattern across blocks 960,778 to 960,792, spanning roughly 2.5 hours, showed 218 transactions hitting 462 victim addresses, with 216 fresh destination wallets receiving 388.92 BTC.
The sweep activity was running at approximately 45 times the normal rate, 13.8 sweeps per block versus a baseline of 0.3. Moreover, every transaction showed zero inputs predating the Coldcard firmware boundary. The topology was 1:1, one fresh destination per victim, with no collector funnel.
After correcting for six addresses with prior transaction history, the surviving core of wave 4 stands at 709 addresses and 448.73 BTC. Also, some stolen funds have already moved to second-hop addresses. Transactions still carrying RBF opt-in signals may offer a narrow window for victims to respond.
What Coldcard Has Done?
Coinkite, the Canadian company behind Coldcard, confirmed the vulnerability and moved quickly. All remaining units at their facilities with affected firmware were destroyed, and the shipments have been halted. Those who had received affected orders were contacted directly with migration steps.
Patched firmware is now available for every affected model, but the fix only protects newly generated seed phrases. Any seed created on the vulnerable firmware remains at risk regardless of the update. Users must generate a new wallet and move all funds immediately.
Satscard, Opendime, and Tapsigner use different codebases and are not affected. For users needing an immediate alternative, Coldcard has suggested Bitkey, Ledger, Trezor, Jade, and Bitbox as temporary options.
Additionally, it has asked the affected users to keep their devices to support any future recovery efforts. The affected firmware versions are Coldcard Mk3, running v4.0.1 through v5.0.3.
An exploit of this scale hitting a device widely regarded as one of Bitcoin’s most trusted cold storage solutions shakes confidence in hardware wallet security broadly.
Crypto Market Highlights
Ethereum (ETH) Falls to $1.8K: Bulls and Bears Clash at a Critical Level




Be the first to comment