Coldcard wallet losses near $114 million as a fourth sweep hits the mempool
What's new in wave four
How the losses stack up
What's driving the exploit
What should affected users do?

India Crypto Research
A fourth wave of thefts targeting bitcoin addresses generated by the Coldcard hardware wallet began early Monday and was still active hours later, pushing the running total of losses toward $114 million. Unlike the first three waves, researchers say this batch of transactions can still be stopped before it settles on the blockchain.
Alex Thorn, head of firmwide research at Galaxy Research, was first to flag the active sweep on X, noting that the attacker had opted into replace-by-fee (RBF), a standard Bitcoin feature that allows an unconfirmed transaction to be overwritten by a new one offering a higher fee. Because these transactions are sitting in the mempool rather than already confirmed, any victim who spots their own address in the queue has a narrow window, likely minutes, to broadcast a competing transaction with a higher fee and move their coins to safety first.
Thorn has said he has not yet had direct confirmation from a victim and published the finding based on pattern-matching in the mempool, choosing to warn the community quickly rather than wait for confirmation.
Across the four waves tracked since July 30, roughly 1,815 BTC — near $114 million at current prices — has been swept from more than 5,290 addresses. The pattern:
Wave 1 (Jul 30): 1,083 BTC pulled from 1,196 addresses in a 41-minute sweep, by far the largest single batch, and the one that first exposed the flaw.
Wave 2 (Jul 31): A much smaller follow-up, roughly 73 BTC.
Wave 3 (Jul 31–Aug 1): About 211 BTC, bringing the three-wave total to 1,367 BTC across 4,585 addresses.
Wave 4 (Aug 3, unconfirmed): An estimated 448 BTC still sitting unconfirmed as of Monday, which, if it clears, would push the cumulative total to roughly 1,815 BTC.
Thorn's analysis of the confirmed pattern found transactions clustered in blocks 960,778 through 960,792, with 218 transactions hitting 462 addresses, a sweep rate of about 14 per block, versus roughly 0.3 in a pre-incident control window. That's about 45 times the normal rate.
The vulnerability traces back to a Coldcard firmware build from March 2021 that generated wallet seeds using a predictable software-based randomizer instead of the device's dedicated hardware random-number generator. That flaw means keys created under the affected firmware are, in principle, reproducible offline by anyone able to work out the narrowed range of possible values, turning what should be an uncrackable secret into a guessable one.
Coinkite, the manufacturer of Coldcard, has since released emergency firmware updates for every affected model and is urging anyone who generated a seed while running the flawed software to move funds to a new wallet created with updated firmware.
Notably, none of the first three waves touched multisignature wallets, consistent with the flaw being isolated to single-key seed generation. Investigators also flagged six destination addresses with years of prior transaction history among the attacker's funds — unusual, since a newly generated attacker-controlled address wouldn't normally have any history — hinting the attacker may be consolidating through older infrastructure.
Thorn's advice to Coldcard users is direct:
Check whether funds sit in a wallet generated under the flawed firmware.
Move any exposed funds to a freshly generated wallet immediately.
If a transaction shows up in the mempool moving your funds, respond immediately with a higher-fee replacement transaction to redirect the funds first.
India Crypto Research operates independently. The information presented herein is intended solely for educational and informational purposes and should not be construed as financial advice. Before making any financial decisions, it's essential to undertake your own thorough research and analysis. If you're uncertain about any financial matters, we strongly recommend seeking guidance from an impartial financial advisor.