A fourth active sweep targeting BTC addresses generated by a flawed 2021 Coldcard firmware has pushed observed losses toward ~1,816 BTC (~$114M) across >5,200 addresses. The attacker's use of replace-by-fee means unconfirmed mempool victims may still override theft attempts by fee-bumping. The incident elevates near-term operational and custody risk for single-key wallets and may tighten liquidity as affected users rotate keys and move funds.
Impact level
● High
Affected assets
BTC/USDT-0.78%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A fourth round of automated "sweeps" targeting bitcoin addresses generated by Coldcard hardware wallets began early Monday and continued for hours. Researchers say this wave may be partially reversible while transactions remain unconfirmed, because the attackers used replace-by-fee (RBF), a Bitcoin option that allows a pending transaction to be replaced by another with a higher fee.
Alex Thorn, head of firmwide research at Galaxy Research, said victims who spot their address in the mempool—Bitcoin's queue of unconfirmed transactions—may be able to outbid the attacker by attaching a higher fee and moving funds first, provided the original transaction has not confirmed.
The activity began July 30, when 1,083 bitcoin were taken from 1,196 addresses in 41 minutes. Two additional waves over the weekend lifted observed losses to 1,367 bitcoin across 4,585 addresses.
Investigators trace the underlying weakness to a March 2021 firmware build that generated seeds using a predictable software randomizer instead of the device chip's hardware random source, potentially allowing private keys to be reproduced offline by anyone who can determine the range.
Coldcard maker Coinkite has issued emergency firmware for all affected models and urged users who created a seed on the flawed version to move funds to addresses generated with a newly created seed.
Thorn said he has not received direct victim reports and published his assessment based on pattern-matching in order to warn users while transactions were still unconfirmed. If the attribution is correct, cumulative losses across four waves have reached about 1,816 bitcoin, roughly $114 million, taken from more than 5,200 addresses since July 30.
Thorn advised users to check balances, move funds off any affected device, and raise fees to beat potentially replaceable transactions. He said the pattern spans blocks 960,778 through 960,792, with 218 transactions affecting 462 victim addresses—about 14 sweeps per block versus 0.3 in a pre-incident control window, or roughly 45 times normal.
Researchers noted that the spent coins arrived after the Coldcard firmware boundary date, and that destination addresses were newly created with no prior history, typically one per victim rather than the shared collection addresses that made the first two waves easier to trace. None of the first three waves hit multisignature setups, consistent with a flaw tied to single-key seed generation. Thorn also flagged six destination addresses with years of prior activity, since newly created attacker addresses would not show historical usage.