BrandLogo
Table of Contents

Coldcard wallet losses near $114 million as a fourth sweep hits the mempool

What's new in wave four

How the losses stack up

What's driving the exploit

What should affected users do?

intermediate

Coldcard wallet losses near $114 million as a fourth sweep hits the mempool

By ICR Research Team|2 mins read
Last Updated on: Aug 11, 2026|Published On: Aug 11, 2026
Key Takeaways
  • Coldcard related losses have reached nearly $114 million, with around 1,815 BTC swept from 5,290+ addresses across four waves.
  • A fourth sweep is still unconfirmed, meaning affected users may have a short window to stop the transaction using RBF (Replace by Fee).
  • The attack traces back to a March 2021 Coldcard firmware vulnerability that used a predictable software based randomiser instead of the device’s hardware RNG.
  • The vulnerability potentially allows attackers to recreate wallet seeds and access funds generated under the affected firmware.
  • The first three waves have already settled, while the fourth wave was still sitting in the mempool when the report was written.
  • The attack appears focused on single key wallets, with multisignature wallets not affected in the observed sweeps.
  • Affected users should immediately move funds from wallets generated under the vulnerable firmware to a newly generated wallet using updated firmware.
  • The incident highlights an important lesson for hardware wallet users: the security of the device depends not just on the hardware, but also on the randomness used to generate the wallet seed.
India Crypto Research

Coldcard wallet losses near $114 million as a fourth sweep hits the mempool

India Crypto Research

A fourth wave of thefts targeting bitcoin addresses generated by the Coldcard hardware wallet began early Monday and was still active hours later, pushing the running total of losses toward $114 million. Unlike the first three waves, researchers say this batch of transactions can still be stopped before it settles on the blockchain.

Blog_Image

What's new in wave four

Alex Thorn, head of firmwide research at Galaxy Research, was first to flag the active sweep on X, noting that the attacker had opted into replace-by-fee (RBF), a standard Bitcoin feature that allows an unconfirmed transaction to be overwritten by a new one offering a higher fee. Because these transactions are sitting in the mempool rather than already confirmed, any victim who spots their own address in the queue has a narrow window, likely minutes, to broadcast a competing transaction with a higher fee and move their coins to safety first.

Thorn has said he has not yet had direct confirmation from a victim and published the finding based on pattern-matching in the mempool, choosing to warn the community quickly rather than wait for confirmation.

Blog_Image

How the losses stack up

Across the four waves tracked since July 30, roughly 1,815 BTC — near $114 million at current prices — has been swept from more than 5,290 addresses. The pattern:

Wave 1 (Jul 30): 1,083 BTC pulled from 1,196 addresses in a 41-minute sweep, by far the largest single batch, and the one that first exposed the flaw.

Wave 2 (Jul 31): A much smaller follow-up, roughly 73 BTC.

Wave 3 (Jul 31–Aug 1): About 211 BTC, bringing the three-wave total to 1,367 BTC across 4,585 addresses.

Wave 4 (Aug 3, unconfirmed): An estimated 448 BTC still sitting unconfirmed as of Monday, which, if it clears, would push the cumulative total to roughly 1,815 BTC.

Thorn's analysis of the confirmed pattern found transactions clustered in blocks 960,778 through 960,792, with 218 transactions hitting 462 addresses, a sweep rate of about 14 per block, versus roughly 0.3 in a pre-incident control window. That's about 45 times the normal rate.

What's driving the exploit

The vulnerability traces back to a Coldcard firmware build from March 2021 that generated wallet seeds using a predictable software-based randomizer instead of the device's dedicated hardware random-number generator. That flaw means keys created under the affected firmware are, in principle, reproducible offline by anyone able to work out the narrowed range of possible values, turning what should be an uncrackable secret into a guessable one.

Coinkite, the manufacturer of Coldcard, has since released emergency firmware updates for every affected model and is urging anyone who generated a seed while running the flawed software to move funds to a new wallet created with updated firmware.

Notably, none of the first three waves touched multisignature wallets, consistent with the flaw being isolated to single-key seed generation. Investigators also flagged six destination addresses with years of prior transaction history among the attacker's funds — unusual, since a newly generated attacker-controlled address wouldn't normally have any history — hinting the attacker may be consolidating through older infrastructure.

What should affected users do?

Thorn's advice to Coldcard users is direct:

Check whether funds sit in a wallet generated under the flawed firmware.

Move any exposed funds to a freshly generated wallet immediately.

If a transaction shows up in the mempool moving your funds, respond immediately with a higher-fee replacement transaction to redirect the funds first.

Disclaimer

India Crypto Research operates independently. The information presented herein is intended solely for educational and informational purposes and should not be construed as financial advice. Before making any financial decisions, it's essential to undertake your own thorough research and analysis. If you're uncertain about any financial matters, we strongly recommend seeking guidance from an impartial financial advisor.