Alex Thorn, research director at Galaxy Research, reported on August 3 that a fourth wave of suspected attacks against cold wallet Coldcard hardware wallet users had emerged. The latest round of attacks transferred approximately 388.9 BTC through 218 transactions in just a few hours, affecting 462 potential victim addresses.
Root cause of attack: Firmware flaw
These attacks can be traced to a vulnerability in the March 2021 Coldcard firmware release. The vulnerability allows attackers to systematically steal Bitcoin from thousands of wallets by recreating keys generated randomly based on weak software. In a functioning hardware wallet, mnemonic words are created through a dedicated random number generator. Coldcard's firmware was supposed to rely on a dedicated hardware random number generator to generate the random number, but an internal build setting instructed it to skip the generator. So the key generation process turned to a basic software alternative that took the chip serial number and clock register as seeds.
Because each Bitcoin private key originates from the seed, once an attacker can reproduce the seed, he can derive the same wallet and empty the funds without touching the physical device. Coinkite released the patched firmware, but the seeds generated under the vulnerable version are still at risk and cannot be repaired through updates. Security companies have warned that more wallets could face attacks because users cannot reliably determine whether their seeds were generated on vulnerable firmware.
Scale of damage and persistent threat
Prior to the fourth wave of attacks, Galaxy Research had identified three waves of theft involving a total of 4585 addresses and 1367 BTC (approximately US$88.6 million) were stolen. Thorne detailed that in the fourth wave of attacks alone, in approximately two and a half hours, 388.93 BTC items were transferred from 462 victim addresses to 216 newly created addresses through 218 transactions.
Thorne pointed out that some transactions are still in the memory pool, which means affected users may still have a chance to protect their funds. He suggested using the Replace-By-Fee (RBF) feature to add a higher fee, potentially covering pending transactions. Thorne described such money sweeps as deliberate and could be manipulated by artificial intelligence, and warned that all single-signed Coldcard addresses created since the firmware vulnerability emerged in March 2021 will eventually be cleared.
This incident has become one of the largest attacks on Bitcoin's self-hosting, not through malware, phishing or exchange vulnerabilities, but rather through flaws in the encryption key generation process. Security experts said that as cyber threats continue to evolve, the hack highlights growing operational risks in the self-custody space and could accelerate the adoption of regulated custodians and spot Bitcoin ETFs.
Any user who holds BTC at a Coldcard generated address and has not yet transferred funds should immediately use another unaffected wallet to transfer funds based on the newly generated mnemonic.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC