Coldcard wallet holders got hit again. Galaxy Research head Alex Thorn flagged a likely fourth organized sweep against Coldcard-generated addresses. This COLDCARD Hack Update adds roughly 388.9 of bitcoin to a theft that already ranks among the largest hardware wallet failures on record.

That single window pushed the running total from this Bitcoin cold wallet exploit well past $88 million in stolen funds. On-chain trackers, including Onchain Lens, are now hinting towards the same collector addresses that absorbed the earlier waves.
Alex Thorn posted the numbers directly from his own research feed. Over a roughly two-and-a-half-hour window, 388.93 BTC moved through 218 transactions from 462 victim addresses to 216 newly created addresses.
Onchain Lens data separately points to the same destination cluster, tying this sweep to the collector wallets already holding funds from the earlier waves.

The activity averaged 13.8 transfers per block, roughly 45 times the level seen during a prior control period.That kind of jump points to a scripted, automated sweep rather than scattered individual theft.
At a Glance
218 transactions across 462 victim addresses
216 fresh destination wallets, mostly one-to-one
Roughly 388.9 BTC moved in total
Some funds have already been moved to second-hop addresses
Thorn's research also offered a narrow lifeline. Some of the transactions are still in the mempool, meaning affected holders may still have a window to protect their funds.

He suggested using Replace-By-Fee to attach higher fees, which could potentially override the pending transactions. Anyone with an at-risk address should raise fees immediately and opt into RBF before confirmation locks the sweep in.
This COLDCARD MK3 vulnerability entered the codebase on March 1, 2021. A commit changed the seed-generation call so it routed through a broken software path instead of the secure hardware chip.
Firmware built on that flaw shipped for more than five years before anyone caught it.
The first confirmed sweep hit fast and hard. An attacker drained roughly 594 bitcoin, worth about $38 million, from around 500 single-signature wallets in under 30 minutes.
A second and third wave followed within days, and Galaxy Research says a third wave alone removed 207.73 BTC, lifting the observed total to about 1,367 BTC.
The stolen coins had sat untouched for an average of 3.18 years, showing most victims were long-term holders rather than active traders.
This fourth wave now pushes the running bitcoin hack news total past 1,367 BTC across 4,585 addresses, worth close to $88.6 million before counting this week's 388.9 BTC.
Coldcard is not the first wallet brought down by weak randomness. CZ, founder of BNB Chain, pointed to one direct parallel this week. He noted that Trust Wallet faced a nearly identical pseudo-random number generator bug years earlier, one that cost roughly $12 million before the company covered every affected user.

Source: CZ Official
Randstorm-era browser wallets exposed keys through weak entropy
The MilkSad libbitcoin bug relied on a predictable time-based seed
A flawed vanity-address tool contributed to a nine-figure exchange theft
Each case shows the same lesson. Strong hardware security means little if the randomness generating the private key underneath is silently broken.
Coinkite, the maker of Coldcard, has confirmed the root cause. A build-time check meant to confirm a secure setting failed to activate, so affected devices fell back to a weaker software random number generator instead of the intended hardware version.
Coinkite founder Rodolfo Novak also took public responsibility for the failure, calling the company accountable for the firmware error that caused this COLDCARD BTC stolen crisis.
Coinkite has since patched every affected line. Mk4 and Mk5 users must update to version 5.6.0 or later, Q users must update to version 1.5.0Q or later, and Mk3 owners need version 4.2.0 or later.
The update only protects new seeds, though. Anyone who generated a seed on old firmware still needs to create a brand-new seed and move funds off the old addresses immediately. Satscard, Opendime, and Tapsigner products remain unaffected by this Bitcoin cold wallet exploit.
Speed matters most right now. This COLDCARD Hack Update will likely keep growing as researchers trace remaining exposed addresses, so checking firmware version and moving funds today remains the safest move available.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Crypto markets carry significant risk. Always do your own research before making any investment decisions.