
Galaxy Research head Alex Thorn has hinted that Coldcard was hit by a fourth wave of attacks on August 3, estimating that the attackers moved 448.7 BTC from 709 wallets belonging to victims.
Thorn based his findings on blockchain analysis rather than device records, describing the addresses as “likely Coldcard victims.”
Thorn described the addresses hit by the suspected attack as “likely Coldcard victims,” adding that the unspent outputs and transactions matched the vulnerable wallet pattern. Galaxy’s initial snapshot covered blocks 960,778 through 960,792, identifying 218 transactions involving 388.9 BTC and 462 potential victim addresses. The updated estimate expanded the figures to hundreds of transactions involving 448.7 BTC and 709 potential victim addresses.
Thorn posted the findings on X:
“LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURING RIGHT NOW THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS, AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS.”
According to Thorn, Galaxy measured 13.8 sweeps per block, a 45x increase compared to 0.3 sweeps per block measured during a pre-incident control period. The siphoned funds were sent to a new address instead of a shared wallet. Some of the stolen funds were subsequently moved to new addresses, making them difficult to track.
Galaxy has already mapped three prior waves that siphoned 1,367.05 BTC from 4,585 addresses, with the first wave targeting 1,082.05 BTC across 1,196 addresses. The latest wave brings the total figures to 1,815.75 BTC across 5,294 addresses. However, the figures are yet to be confirmed by authorities, Coinkite, or the wallet owners. Additionally, it isn’t clear whether one entity was responsible for all four waves.
Thorn also added that there were transactions awaiting approval in Bitcoin’s mempool, giving holders an escape route. According to Thorn, Bitcoin Core documentation states that unconfirmed opt-in Replace-by-fee transactions can be replaced. This means a user still in control of an affected key could broadcast a conflicting transaction with a higher fee and send the funds to a secure wallet. However, it cannot be replaced once it enters the block, and a replacement is not guaranteed to succeed.
The ongoing issue arises from an RNG integration error that occurred during a March 2021 firmware change. Coinkite estimates that the affected Mk2 and Mk3 seeds have around 40 bits of effective entropy, while seeds generated on affected Mk4, Mk5, and Q releases have 72 bits instead of 128.
Additionally, an engineering team from Block discovered that the firmware called a deterministic MicroPython fallback instead of the hardware random-number generator. However, the Block team clarified they could not confirm exploitability without full empirical testing.
Meanwhile, Coinkite has released version 4.2.0 for Mk2 and Mk3, 5.6.0 for Mk4 and Mk5, 1.5.0Q for Q, and 6.6.0X or 6.6.0QX for Edge releases. However, simply updating the existing firmware does not fully address the vulnerability. Once updated, users must generate a new seed and verify the receiving address. Once verified, they must send a test transaction before migrating the complete balance.
Coinkite also clarified that seeds created using a minimum of 50 fair, private dice rolls are not considered at risk, and that a unique BIP-39 passphrase could serve as a second line of defense. However, it recommended that users complete the migration. The advisory does not cover TAPSIGNER, OPENDIME, and SATSCARD because they use separate codebases.
Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.
This article was originally published as Coldcard Hit By Suspected Fourth Attack Wave As Losses Mount on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.