A new wave of coordinated thefts is sweeping through the Bitcoin ecosystem, targeting users of Coldcard hardware wallets. Coming just days after an initial series of exploits, this latest attack has already compromised hundreds of addresses and siphoned off millions of dollars worth of cryptocurrency.
Security researchers are urging affected users to act immediately, as unconfirmed transactions currently sitting in the mempool may offer a narrow window of opportunity to intercept stolen funds before they are lost for good.
Galaxy Research Flags 448 BTC Swept Across Hundreds of Addresses
According to an update from Galaxy head of research Alex Thorn, the fourth wave of attacks has seen approximately 448.7 Bitcoin (BTC) moved out of 709 potential victim addresses. The rapid automated activity averaged roughly 13.8 sweeps per block—a dramatic surge operating at roughly 45 times the rate of typical network activity observed before the exploit.
Unlike traditional exploits where stolen funds flow directly into a centralized hacker wallet, this attack uses a more fragmented strategy. Thorn noted that the transfers generally route funds into a unique, freshly created destination address for each victim. From there, several transactions have already begun moving funds into secondary “second-hop” addresses to obfuscate the trail.
Given the distinct structural footprint of the vulnerable Unspent Transaction Outputs (UTXOs) and the rapid spike in transaction volume, researchers have high confidence that these incidents are directly linked to the broader Coldcard compromise.
Critical Firmware Flaw Exposes Wallets: How Affected Users Can Intercept Attacks
The underlying cause of the widespread sweeps traces back to a recently disclosed, previously undetected vulnerability in Coldcard’s firmware. The flaw caused affected devices to generate wallet seeds with significantly lower entropy—or randomness—than intended. This structural weakness made it possible for attackers to predict seed phrases and systematically drain the associated funds. Estimates indicate that thousands of wallets have been compromised so far, with total losses surpassing $90 million in Bitcoin.
For users who suspect their wallets might be vulnerable, there is still a small glimmer of hope. Thorn pointed out that additional malicious transactions are currently waiting in the Bitcoin mempool for network confirmation.
Because these transactions are not yet permanently written to the blockchain, affected keyholders who act quickly may be able to perform a Replace-By-Fee (RBF) or broadcast a conflicting transaction with a higher miner fee. By paying a higher fee to prioritize their transaction, users can attempt to move their remaining funds to a freshly generated, secure wallet before the attacker’s transaction is confirmed by miners. Anyone utilizing a Coldcard setup generated during the vulnerable firmware window is strongly advised to check their transaction status and transfer any remaining balances immediately.