COLDCARD Hack Update: Fourth Attack Wave Hits 462 Addresses Now

COLDCARD Hack Update: Fourth Wave Wiped Out 388.9 BTC

COLDCARD Hack Update: New BTC Sweep Targets Hundreds of Addresses

Coldcard wallet holders got hit again. Galaxy Research head Alex Thorn flagged a likely fourth organized sweep against Coldcard-generated addresses. This COLDCARD Hack Update adds roughly 388.9 of bitcoin to a theft that already ranks among the largest hardware wallet failures on record. 

Alex Thorn flagged a likely fourth organized sweep

That single window pushed the running total from this Bitcoin cold wallet exploit well past $88 million in stolen funds. On-chain trackers, including Onchain Lens, are now hinting towards the same collector addresses that absorbed the earlier waves.

COLDCARD Hack Update: Fourth Wave Sweeps 388.9 BTC

Alex Thorn posted the numbers directly from his own research feed. Over a roughly two-and-a-half-hour window, 388.93 BTC moved through 218 transactions from 462 victim addresses to 216 newly created addresses. 

Onchain Lens data separately points to the same destination cluster, tying this sweep to the collector wallets already holding funds from the earlier waves.

ColdCatd Exploit Loss Reaches $88.6M

The activity averaged 13.8 transfers per block, roughly 45 times the level seen during a prior control period.That kind of jump points to a scripted, automated sweep rather than scattered individual theft.

At a Glance

  • 218 transactions across 462 victim addresses

  • 216 fresh destination wallets, mostly one-to-one

  • Roughly 388.9 BTC moved in total

  • Some funds have already been moved to second-hop addresses

Thorn's research also offered a narrow lifeline. Some of the transactions are still in the mempool, meaning affected holders may still have a window to protect their funds. 

Thorn research offered a narrow lifeline

He suggested using Replace-By-Fee to attach higher fees, which could potentially override the pending transactions. Anyone with an at-risk address should raise fees immediately and opt into RBF before confirmation locks the sweep in. 

COLDCARD Hack Update: Total Losses Climb Past 1,367 BTC Across Four Attack Waves

This COLDCARD MK3 vulnerability entered the codebase on March 1, 2021. A commit changed the seed-generation call so it routed through a broken software path instead of the secure hardware chip. 

Firmware built on that flaw shipped for more than five years before anyone caught it.

The first confirmed sweep hit fast and hard. An attacker drained roughly 594 bitcoin, worth about $38 million, from around 500 single-signature wallets in under 30 minutes. 

A second and third wave followed within days, and Galaxy Research says a third wave alone removed 207.73 BTC, lifting the observed total to about 1,367 BTC. 

The stolen coins had sat untouched for an average of 3.18 years, showing most victims were long-term holders rather than active traders. 

This fourth wave now pushes the running bitcoin hack news total past 1,367 BTC across 4,585 addresses, worth close to $88.6 million before counting this week's 388.9 BTC.

Other Cases: Weak Random Numbers Bugs Have Hit Crypto Wallets Before This Attack

Coldcard is not the first wallet brought down by weak randomness. CZ, founder of BNB Chain, pointed to one direct parallel this week. He noted that Trust Wallet faced a nearly identical pseudo-random number generator bug years earlier, one that cost roughly $12 million before the company covered every affected user.

Trust Wallet faced a nearly identical number generator bug

Source: CZ Official

Other cases follow the same pattern:

  • Randstorm-era browser wallets exposed keys through weak entropy

  • The MilkSad libbitcoin bug relied on a predictable time-based seed

  • A flawed vanity-address tool contributed to a nine-figure exchange theft

Each case shows the same lesson. Strong hardware security means little if the randomness generating the private key underneath is silently broken.

Coinkite Response: Firmware Fix And Fund Recovery Steps Explained

Coinkite, the maker of Coldcard, has confirmed the root cause. A build-time check meant to confirm a secure setting failed to activate, so affected devices fell back to a weaker software random number generator instead of the intended hardware version. 

Coinkite founder Rodolfo Novak also took public responsibility for the failure, calling the company accountable for the firmware error that caused this COLDCARD BTC stolen crisis. 

Coinkite has since patched every affected line. Mk4 and Mk5 users must update to version 5.6.0 or later, Q users must update to version 1.5.0Q or later, and Mk3 owners need version 4.2.0 or later.  

The update only protects new seeds, though. Anyone who generated a seed on old firmware still needs to create a brand-new seed and move funds off the old addresses immediately. Satscard, Opendime, and Tapsigner products remain unaffected by this Bitcoin cold wallet exploit.

Speed matters most right now. This COLDCARD Hack Update will likely keep growing as researchers trace remaining exposed addresses, so checking firmware version and moving funds today remains the safest move available.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Crypto markets carry significant risk. Always do your own research before making any investment decisions. 

Bhumika Baghel

About the Author Bhumika Baghel

English News Writer at coingabbar.com

Bhumika Baghel is a crypto journalist at Coin Gabbar with over 1.5 years of industry experience. She specializes in SEO-optimized content, market trend research, and fast-paced news reporting across cryptocurrency developments, along with regulatory updates, token presales, and emerging blockchain technologies. Maintaining an independent and unbiased editorial approach, Bhumi focuses on delivering clear, timely, and objective analysis.
Leave a comment

Frequently Asked Questions (FAQ)

Faq Got any doubts? Get In Touch With Us
Scroll to Top