Loading market data...
Back to Feed
CRYPTO NEWS

Coldcard wallet losses may near $114 million as possible fourth sweep emerges

Reported by CoinDesk · AI-assisted summary by ChikoCorp AI News Desk

Published on CryptoNews: Source published: 2 min read
AI-generated editorial illustration for Coldcard wallet losses may near $114 million as possible fourth sweep emerges
AI-generated editorial illustration.
Visit source

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.

$114 million

Summary

A fourth wave of bitcoin thefts targeting Coldcard-generated wallet addresses has been identified, with attackers moving approximately 1,816 bitcoin, valued near $114 million, from over 5,200 addresses since July 30, 2026. The attacks exploit a flaw in Coldcard's firmware from March 2021 that results in predictable key generation. Unlike earlier waves, the latest transactions use Bitcoin’s replace-by-fee feature, allowing victims a chance to reclaim funds by outbidding the attacker before confirmation.

Why it matters

The ongoing sweeps highlight a significant security vulnerability in Coldcard cold wallets, affecting single-key seeds and leading to substantial potential losses. The use of replace-by-fee in the latest wave may provide victims with an opportunity to counteract the attacks before funds are irreversibly moved. This situation underscores the importance of timely detection and response in crypto asset security.

Key context

The flaw stems from a Coldcard firmware released in March 2021 that misrouted seed generation, making private keys reproducible by anyone who can determine the key range. Three prior waves of attacks between July 30 and early August 2026 cumulatively moved more than 1,300 bitcoin. Coldcard manufacturer Coinkite issued an emergency firmware update and advised users with vulnerable seeds to transfer funds to new addresses created by unaffected firmware versions. The replace-by-fee feature lets pending transactions be replaced by those paying higher fees until confirmation, enabling a possible defense against theft.

Key numbers and entities

The attacker moved about 1,816 bitcoin (approximately $114 million) from more than 5,200 addresses since July 30, 2026. The initial sweep took 1,083 bitcoin from 1,196 addresses in 41 minutes. Related blocks range from 960,778 to 960,792, with 218 transactions affecting 462 addresses. Alex Thorn, head of firmwide research at Galaxy Research, flagged and analyzed the activity. Coldcard and its manufacturer Coinkite are the impacted wallet and company.

What remains unclear

Alex Thorn noted he has no direct reports from victims and based his findings on transaction pattern matching rather than confirmed user accounts. It is unknown how many affected users have successfully reclaimed funds using replace-by-fee or whether all vulnerable wallets have been identified. The long-term impact or resolution timeline is not provided.

Read the original source

> JOIN THE ALPHA

Get a free crypto news briefing in your inbox. No fake subscriber counts — just the latest source-backed headlines we cache.

>
[ENCRYPTED][NO_SPAM][UNSUBSCRIBE_ANYTIME]