Suspected 4th Coldcard attack wave sweeps 389 Bitcoin: Galaxy’s Thorn
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
A new wave of coordinated thefts is targeting Coldcard Bitcoin hardware wallets, with 218 transactions affecting 462 potential victim addresses reported recently. Galaxy research head Alex Thorn highlighted that around 388.9 BTC has been moved, with these transactions likely linked to a Coldcard firmware flaw causing weak wallet seeds. This is the fourth such attack wave detected within days.
Why it matters
The ongoing thefts represent a significant security risk for Coldcard hardware wallet users, with millions of dollars in Bitcoin already stolen. The elevated transaction activity indicates a coordinated campaign that could impact many users and challenge trust in hardware wallet security. Users still controlling their keys may have a chance to protect their funds by broadcasting conflicting transactions.
Key context
The attacks follow the discovery of a previously unknown Coldcard firmware vulnerability that lowered the entropy of wallet seed generation. This flaw has affected thousands of wallets and led to over $90 million in Bitcoin thefts so far. Attackers create new destination addresses per victim, complicating tracking and recovery efforts. The current wave shows transaction rates about 45 times normal levels observed before the incidents.
Key numbers and entities
The key entities are Coldcard hardware wallet users and Galaxy researcher Alex Thorn. Important figures include 218 suspect transactions, 462 potential victim addresses, 388.9 BTC moved, and an estimated $90 million in Bitcoin stolen across all waves. Thorn also noted an average of 13.8 sweeps per block, far exceeding previous rates.
What remains unclear
The report does not specify the exact method attackers use beyond exploiting the firmware flaw or how many total wallets remain vulnerable. It also does not confirm whether all funds are irretrievable, though it suggests users may preemptively secure their assets. The source does not flag other open questions.