Coldcard Thefts Near $114 Million as Fourth Attack Wave Hits

Attackers began a fourth wave of sweeps against bitcoin held in Coldcard hardware wallets on Monday, pushing estimated losses to roughly $114 million since Thursday. The latest transactions remained replaceable in the mempool, giving some victims a brief window to move their coins before the thefts confirm.
The thefts stem from a firmware bug that shipped in March 2021 and went unnoticed for more than five years, undercutting the core promise of hardware wallets: that keys generated on the device cannot be guessed. Coldcard maker Coinkite has released emergency firmware for every affected model, halted shipments, and told users to move funds to freshly generated seeds.
Alex Thorn, head of firmwide research at Galaxy, flagged the new wave early Monday, counting 448.7 BTC swept from 709 potential victim addresses at a rate of 13.8 sweeps per block — about 45 times the rate in a pre-incident control window. That comes on top of the 1,367 BTC taken from 4,585 addresses across three earlier waves, bringing the estimated total to about 1,816 BTC from more than 5,200 addresses.
"These are LIKELY Coldcard victims — they match the shape of coldcard vulnerable utxos and the elevated transaction pattern gives me high confidence they are another wave of attacks," Thorn wrote.
Bitcoin traded at about $62,600 on Monday, according to CoinGecko.
A Race in the Mempool
Unlike the earlier waves, Monday's transactions opted into replace-by-fee, a Bitcoin feature that lets an unconfirmed transaction be overwritten by a later one paying a higher fee. Until the attacker's transaction confirms, a victim who spots their address in the mempool can broadcast a conflicting transaction with a higher fee and move the coins to a safe wallet first.
Thorn urged affected users to check their funds and bid the fee up. The window is short: it lasts only as long as the attacker's transaction sits unconfirmed.
The attacker also changed tactics. Where the first waves converged on shared collection wallets that were easy to map, Monday's sweeps sent funds to a fresh, previously unused address for each victim, making the flows harder to trace.
One Wrong Function Call
The first wave hit on Thursday, July 30, draining more than 1,000 BTC in under an hour, and by that evening both Coinkite and outside researchers had published post-mortems. Block's Bitcoin Engineering and Security teams, working with anonymous researchers, traced the root cause to a March 1, 2021 commit that migrated Coldcard's seed generation to a new cryptography library.
The change routed seed generation to MicroPython's Yasmarang software randomizer — seeded from the chip's serial number and timer registers — instead of the device's hardware random-number generator. Because both functions shared a name, the build completed without error, and the flawed path shipped in firmware v4.0.0 on March 17, 2021.
The result, per Block's analysis: seeds generated on Mk2 and Mk3 devices running v4 firmware are reproducible offline by anyone who can constrain the device's serial number and boot timing. Later devices — the Mk4, Mk5 and Q — added a partial fix that reseeds the generator with secure-element entropy, but only 32 bits of it reach the generator. Coinkite says those seeds carry about 72 bits of entropy instead of the intended 128 — a less severe weakness, but still serious.
A wallet's public address gives attackers a way to check candidate keys, so weak seeds can be brute-forced and drained without ever touching the device.
'Move Your Funds Now'
Coinkite published its security advisory on July 30 and has since released fixed firmware for every model: version 4.2.0 for Mk2/Mk3, 5.6.0 for Mk4/Mk5, 1.5.0Q for the Q, and 6.6.0X/QX on the Edge track. Updating does not repair an existing seed — users who generated seeds on affected firmware must create a new seed on fixed firmware and migrate their funds.
"If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further," Coinkite CEO Rodolfo Novak, known as NVK, wrote in an open letter posted to X. "I'm sorry and I'm devastated. Our team is heartbroken about yesterday's news."
The company said it halted Coldcard shipments as soon as it confirmed the vulnerability and destroyed all remaining units at its facilities with affected firmware installed. Customers whose orders had already shipped were contacted by email with migration steps.
Dice Rolls and Passphrases
Coinkite says seeds created with at least 50 fair, private dice rolls through the device's Add Dice Rolls feature are not at risk from the RNG issue alone, since the dice input contributed at least 128 bits of independent entropy. A strong, unique BIP-39 passphrase adds a separate barrier, though Coinkite says passphrase users should still migrate.
None of the attack waves so far has touched multisig setups, consistent with the flaw affecting single-key seeds — though Block warned that a multisig composed entirely of vulnerable devices offers no protection. Coinkite's other products — Tapsigner, Satscard and Opendime — run different codebases and are unaffected.
The episode lands on a hardware-wallet industry already under scrutiny: thieves stole $282 million in bitcoin and litecoin in January through a social-engineering scam targeting hardware wallet users, an attack that relied on tricking victims rather than breaking the devices' cryptography. The Coldcard flaw is different in kind: users who followed best practices — bought directly from the manufacturer, kept devices air-gapped, verified firmware — still generated guessable keys.
Advertisement
Get an edge in Crypto with our free daily newsletter
Know what matters in Crypto and Web3 with The Defiant Daily newsletter, Mon to Fri
90k+ Defiers informed every day. Unsubscribe anytime.



