Alex Thorn warns: A fourth wave of Bitcoin theft against Coldcard users strikes
Alex Thorn, director of research at Galaxy Digital, reports that a fourth wave of theft against Coldcard hardware wallet users has emerged. Thorn detailed in a series of posts that in approximately two and a half hours, a total of 388.93 bitcoins were transferred from 462 victim addresses to 216 newly created addresses through 218 transactions. Previously, more than 1,359.88 bitcoins had been stolen due to a random number generation vulnerability in Coldcard firmware.
Attack patterns and urgency
Thorn pointed out that some transactions are still in the memory pool, which means affected users may still have time to protect their funds. He suggested using an alternative fee mechanism to add higher fees, making it possible to cover pending transactions. The fact that trading frequencies soared to about 45 times normal levels highlights the urgency of the situation and strongly suggests that this was an organized and sustained attack.
All unspent transaction output involved in these transactions was created by defective Coldcard firmware and pointed to systemic vulnerabilities rather than isolated user errors. The attack appears to exploit a known issue that has caused significant damage in previous waves of attacks.
Background and Impact
Coldcard users were severely injured earlier this year when a random number generation vulnerability allowed attackers to leak private keys, resulting in the theft of more than 1,359.88 bitcoins. In response, Coldcard issued an emergency firmware update, but reports quickly emerged that some devices were bricked and could not boot after installation, further exacerbating the confusion.
The current wave of attacks highlights the continuing risks faced by hardware wallet users, even those who rely on devices known for their security. For those affected, the immediate advice is to monitor the memory pool and consider using an alternative fee mechanism if the transaction is still pending. The broader lesson, however, is to focus on firmware patch updates and understand the limitations of any secure device.
Why this matters
This incident is a stark reminder that hardware wallets, while generally safe, are not invulnerable. Coldcard's random number generation flaw is particularly worrying because it directly undermines the wallet's cryptographic foundation. For the broader cryptocurrency community, this highlights the importance of strict security audits and timely firmware updates, while also raising questions about manufacturer responsibilities and products should be designed securely.
Conclusion
The fourth wave of theft against Coldcard users pointed out by Alex Thorn is an ongoing incident that requires immediate attention from those affected. Trading patterns and attack speed suggest that a sophisticated opponent is exploiting a known vulnerability. Despite the huge financial losses, this incident also reminds us that threats in the cryptocurrency field are constantly evolving and we need to be vigilant at all times.
FAQ
Q: If I am a Coldcard user and suspect that funds are at risk, what should I do?
Answer: If you suspect that funds are risky, first check the memory pool to see if there are pending transactions from your wallet. If an unauthorized transaction is discovered, you can try using an alternative fee mechanism to increase the fee to cover the transaction. Immediately transfer the remaining funds to your secure wallet and update the firmware to the latest version, but be aware of issues caused by recent emergency updates.
Question: How to prevent this kind of theft in the future?
Answer: Always ensure that the hardware wallet firmware is the latest version and verify the authenticity of the update through official channels. For large amounts of money, consider using multi-signature settings and regularly review wallet security features. In addition, keep abreast of known vulnerabilities and security bulletins issued by manufacturers and the community.
Question: Is it safe to continue using Coldcard wallet after this incident?
Answer: Although Coldcard has resolved the random number generation vulnerability through firmware updates, recent brick issues suggest that users should proceed with caution. It is recommended to test updates on your wallet with a small amount of money first. If you are worried about asset security, consider other hardware wallets. Be sure to weigh risks and pay attention to the latest security developments.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC