Coldcard Hit by Fourth Coordinated Theft Wave; 388.9 BTC Drained Across 14 Blocks

AI Market Summary
A fourth organized theft wave targeting vulnerable Coldcard-generated seeds reportedly drained ~388.9 BTC from 462 addresses within 14 blocks, with high-velocity consolidation into fresh destinations and some funds already moving to second-hop wallets. Pending mempool activity and RBF opt-in suggest limited mitigation for a subset of victims, but the episode reinforces ongoing self-custody and hardware-wallet lifecycle risk, weighing on near-term crypto sentiment.
Impact level
● Medium
Affected assets
BTC/USDT-0.86%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Coldcard wallet users are confronting a fourth round of coordinated theft, with losses accelerating. Alex Thorn, Head of Research at Galaxy Research, reported a new surge of suspicious on-chain activity that removed about 388.9 BTC from 462 victim addresses over a tight 14-block span, from blocks 960,778 through 960,792. The sweep involved 218 transactions that consolidated funds into 216 previously unseen destination addresses. Galaxy Research said transaction volume jumped to roughly 45 times the pre-incident baseline, pointing to an organized, scripted operation rather than opportunistic theft. The original report also noted that part of the stolen bitcoin has already been traced to second-hop addresses, while additional similar transactions remain queued in the mempool, suggesting the process is still underway. On-chain data indicates the outgoing transactions opted in to Replace-by-Fee (RBF). That detail may give a narrow chance of recovery for victims who identify the drain quickly and can replace still-unconfirmed transactions with higher-fee alternatives to a safe address. ### Fast, coordinated execution Galaxy Research said what distinguishes this wave is its speed and coordination: 462 addresses were hit within a compressed block window, and the outflows were routed to addresses with no prior history. The combination of fresh destination addresses, rapid consolidation, and volumes far above normal is consistent with pre-planned automation. The activity occurred over a weekend, when many holders may not have been monitoring their wallets. ### A continuing pattern of organized theft Galaxy Research previously identified three separate campaigns targeting Coldcard-generated addresses. Across those earlier waves, attackers drained a cumulative 1,367.05 BTC from 4,585 addresses, worth about $88.6 million at the time of the thefts. Those incidents led Coldcard to acknowledge a firmware vulnerability that allowed attackers to derive private keys from seeds created on affected devices. The company halted shipments and destroyed remaining COLDCARD units carrying the vulnerable firmware. It said Satscard, Opendime, and Tapsigner were not affected. Coldcard has released patched firmware that protects newly generated seeds, but the fix does not apply retroactively. Any seed created while running the vulnerable firmware remains compromised. The company's guidance is to generate a new seed on the patched firmware and move all funds off addresses tied to old seeds immediately. The latest wave suggests many users have not yet completed that migration. ### User guidance as attacks persist Coldcard's move to stop shipments and destroy inventory underscored that the flaw was not merely theoretical. Even so, remediation is operationally burdensome for self-custody users: generating a new seed forces an address overhaul and can require changes across software wallets, multisig configurations, and backup procedures. Galaxy Research urged users still holding funds on seeds created under the vulnerable firmware to move assets immediately, use higher-than-usual fees to ensure confirmation, and use RBF where available. The scale of this latest drain suggests attackers are actively monitoring for remaining balances. ### Broader implications for self-custody security Beyond a single firmware bug, the Coldcard incident highlights supply-chain and lifecycle risks embedded in self-custody. A seed-generation flaw that persists undetected can lead to prolonged, difficult cleanup, especially if users delay migration. Galaxy Research noted the spacing of four distinct waves, months apart, suggests a patient attacker with a reliable method for linking compromised seeds to addresses, potentially from a dataset captured during a period of weak randomness. It remains unclear whether the attacker has the full set of compromised seeds or only a subset, and whether other undisclosed vulnerabilities exist in earlier firmware versions. With 462 addresses affected in this wave, Galaxy Research warned the total losses could rise if systematic sweeping continues. For the broader hardware wallet industry, the episode reinforces that rigorous firmware audits and transparent vulnerability disclosure are central to the security model, not optional add-ons.