×

Bitcoin Losses From Coldcard Flaw Surge Toward $114M After Suspected New Exploit Wave

Bitcoin Losses From Coldcard Flaw Surge Toward $114M After Suspected New Exploit Wave

A fourth round of Bitcoin sweeps linked to the Coldcard wallet exploit began early Monday and continued for several hours. However, researchers said this latest wave differs from previous attacks because the transactions remain unconfirmed, meaning victims may still have an opportunity to replace them.

Alex Thorn, Galaxy Research’s head of firmwide research, identified the ongoing activity and said the attackers enabled Bitcoin’s replace-by-fee (RBF) feature. This allows a pending transaction to be replaced with a new one that carries a higher fee. If users notice their addresses appearing in the mempool — the waiting area for unconfirmed Bitcoin transactions — they may be able to submit a higher-fee transaction and transfer their coins before the attacker’s transaction is confirmed.

The Coldcard-related theft campaign began on July 30, with the first wave removing 1,083 BTC from 1,196 addresses in just over 40 minutes. Two additional waves during the weekend increased the confirmed losses to 1,367 BTC across 4,585 addresses.

The root cause of the exploit was traced to a March 2021 Coldcard firmware flaw that weakened seed generation. The affected software mistakenly used a predictable software-based random number generator instead of the device’s hardware random number generator, allowing attackers to recreate private keys offline from vulnerable seeds.

Coldcard manufacturer Coinkite released emergency firmware updates for impacted devices and instructed users who created wallet seeds on affected firmware versions to generate new wallets and move their funds to addresses created from fresh seeds.

Thorn said he did not have direct confirmation from individual victims and that his analysis was based on blockchain data, transaction patterns, and address similarities. He released the findings quickly because some attacker transactions were still pending, giving users a limited chance to act.

If the latest activity is confirmed, the total amount stolen across all four waves would reach around 1,816 BTC, worth approximately $114 million, affecting more than 5,200 addresses since July 30.

Thorn advised users who may have been impacted to immediately check their wallets, transfer assets away from vulnerable devices, and increase transaction fees when attempting to move funds ahead of the attacker’s pending transactions.

The fourth wave was detected across blocks 960,778 to 960,792, involving 218 transactions targeting 462 victim addresses. The attackers conducted around 14 sweeps per block, compared with an average of roughly 0.3 sweeps per block before the incident — about 45 times higher than normal activity.

Analysis showed that the affected coins came from wallets created after the vulnerable Coldcard firmware period, while the receiving addresses were newly generated and had no previous transaction history. Unlike earlier waves that used shared destination wallets, making them easier to track, the latest wave appeared to send stolen funds to separate addresses for individual victims.

The first three attack waves did not involve multisignature wallets, indicating that the vulnerability mainly affected single-key wallet setups. Researchers also found six destination addresses with earlier transaction activity, suggesting that some receiving addresses were not freshly created by the attacker.

Share this content:

Copyright © 2025 CoinsNewz