Fourth Wave of Coldcard Wallet Attacks Threatens Nearly 449 BTC

A suspected fourth wave of attacks targeting vulnerable Coldcard generated Bitcoin wallets is underway, placing nearly 449 BTC at risk. Blockchain researcher Alex Thorn warned on August 3 that attackers had already swept hundreds of wallets in just over two hours, with the operation still ongoing at the time of his analysis.

The latest incident follows three earlier attack waves that researchers believe are linked to the same weak entropy vulnerability affecting certain versions of Coldcard firmware.

Hundreds of Wallets Targeted

According to Thorn, the latest wave involved 218 transactions affecting 462 suspected victim addresses between Bitcoin blocks 960778 and 969792. Around 388.93 BTC, worth approximately $24.4 million at current prices, was transferred to 216 destination addresses, almost all of which were newly created and had no previous transaction history.

Thorn said the transaction patterns closely matched those seen in earlier Coldcard attacks, giving him strong confidence that these wallets were part of the same exploit. However, he noted that he had not yet received direct confirmation from affected users, which is why he described the wallets as likely victims rather than confirmed ones.

After further review, Thorn removed six destination addresses from his original list after discovering they had been active long before the Coldcard attacks began on July 30. Those addresses accounted for just over 5 BTC.

He also excluded 89 multisignature addresses because none had appeared during the first three attack waves. Following those revisions, the total number of affected single signature addresses stood at 709, with approximately 448.73 BTC, valued at about $28.1 million, either already stolen or involved in pending transactions.

Victims May Still Have a Small Window to Act

Thorn urged anyone using affected Coldcard wallets to move their funds immediately and submit transactions with higher network fees.

He also pointed out that some of the attackers’ transactions were broadcast with Replace by Fee enabled. This means victims whose transactions are still waiting in the Bitcoin mempool may have a brief opportunity to increase their transaction fees and potentially have their own transfers confirmed before the attackers’ transactions.

Earlier Stolen Funds Largely Remain Untouched

Galaxy Research estimates that the first three confirmed attack waves drained 1,367 BTC, worth roughly $85.7 million, from 4,585 Bitcoin addresses.

According to the firm, most of the stolen funds remain untouched in wallets controlled by the attackers, suggesting the thefts are part of a coordinated campaign rather than isolated opportunistic attacks.

Not all of the stolen Bitcoin has remained idle, however. One victim who lost nearly 30 BTC reportedly had 17 BTC transferred through ThorChain before ending up at the Duel online casino. The casino allegedly informed the victim that a police report would be required before it could consider freezing the funds.

Vulnerability Traced to Older Firmware

The attacks exploit a vulnerability affecting wallet seeds generated by certain Coldcard firmware versions released after March 2021.

Coinkite, the manufacturer of the Coldcard hardware wallet, confirmed that seeds created on affected Mk3, Mk4, Mk5, and Q devices are vulnerable. Although updated firmware prevents the issue for newly generated seeds, it cannot protect wallets created with the older compromised versions.

The company said it has destroyed all remaining vulnerable inventory, suspended shipments of affected devices, and is working with customers and law enforcement to identify those responsible for the attacks.

Coinkite has also urged users to migrate their funds to a newly generated seed created on an unaffected device. Thorn warned that every single signature Coldcard wallet generated under the vulnerable conditions is ultimately expected to be drained if users fail to move their funds in time.#crypto#cryptonews https://coinsignals.net https://t.me/coinsignalpublic