A fourth organized Coldcard sweep moved 388.93 BTC on Aug. 3, with matching transactions still pending and a Replace-By-Fee window open for victims.
A fourth organized Coldcard sweep moved 388.93 BTC on Aug. 3, with matching transactions still pending and a Replace-By-Fee window open for victims.

Galaxy Research flagged a fourth Coldcard wallet sweep on Aug. 3, moving 388.93 BTC across 218 transactions from 462 victim addresses. The sweep landed in blocks 960,778 through 960,792 over roughly two and a half hours, with additional matching transactions still unconfirmed in the mempool at the time of disclosure.
"These are LIKELY Coldcard victims — they match the shape of coldcard vulnerable utxos and the elevated transaction pattern gives me high confidence they are another wave of attacks," Alex Thorn, head of firmwide research at Galaxy Digital, said on X.
The sweep rate hit 13.8 transfers per block against a pre-incident baseline of 0.3 per block, a roughly 45-fold elevation pointing to an automated pipeline processing a pre-computed list of vulnerable keys. Each victim address was routed to its own fresh destination in a strict one-to-one mapping with no collector wallet consolidating funds — a topology closer to wave 3 than to the earlier waves. After corrections from Bitcoin multisig service Nunchuk and Thorn's own on-chain audit removed 89 multisig false positives and six pre-existing addresses, the revised tally stands at 709 affected addresses and roughly 448.73 BTC.
The cumulative Coldcard drain now approaches 1,816 BTC across more than 5,200 addresses, worth roughly $115 million at current spot levels. Bitcoin traded near the low $63,000s heading into the disclosure, holding despite a 3 percent slide on the initial news and $265 million in Bitcoin ETF redemptions led by BlackRock's IBIT on July 31.
The most operationally significant detail in Thorn's post was not the confirmed batch but the pending one. Matching transactions were still sitting unconfirmed in the mempool with Replace-By-Fee opt-in enabled, meaning the attacker left the door open for a fee war. Affected users who still control their private keys can broadcast a conflicting transaction spending the same UTXOs to a wallet they control at a higher fee rate. Whichever transaction miners find more profitable confirms. Thorn framed it as a minutes-long window to engage in a fee race and secure funds — the first time in the Coldcard incident that a defensive lever has been available to victims in real time.
The root cause traces to a code commit dated March 1, 2021, shipped in Coldcard firmware 4.0.0 later that month. The commit silently rerouted seed generation through a software fallback rather than the intended STM32 hardware random number generator. Mk3 seeds carried roughly 40 bits of effective entropy rather than the 128 bits assumed by BIP-39, and Mk4, Q, and Mk5 seeds around 72 bits due to their secure elements. On commodity hardware, a 40-bit search space is not a barrier.
Coinkite has shipped emergency firmware updates — version 4.2.0 for the Mk3, 5.6.0 for the Mk4 and Mk5, and 1.5.0Q for the Q — but the fixes only apply to newly generated seeds. Anything created on affected firmware is permanently compromised at the seed level. Coinkite has destroyed remaining vulnerable inventory and halted shipments, and CEO Rodolfo Novak has publicly acknowledged the company was unaware of the bug until researchers surfaced it.
The Coldcard incident joins the 2023 Milk Sad PRNG bug and the 2026 Ill Bloom mobile wallet breach as the third major documented failure in this class — all sharing the same brutal characteristic: the failure happens at wallet creation, a moment the user has no way to independently audit. Binance founder Changpeng Zhao publicly warned users not to place blind trust in hardware wallets, and analysts have started asking whether the not-your-keys-not-your-coins mantra needs a second clause about firmware provenance and entropy verification. For anyone still holding funds on a single-signature Coldcard seed created on firmware 4.0.1 or later without additional entropy from dice rolls or a strong BIP-39 passphrase, the standing guidance from both Coinkite and Galaxy Research is unambiguous: generate a fresh seed on an unaffected device, verify the backup, send a test transaction, and only then move the balance.
This article is for informational purposes only and does not constitute investment advice.