Coldcard Wallet Exploit May Be in Fourth Wave, Nearly 449 BTC Potentially Exposed
AI مارکیٹ کا خلاصہ
A suspected fourth wave exploiting weak-entropy seed generation in certain Coldcard firmware versions is reportedly sweeping hundreds of vulnerable Bitcoin addresses, with ~449 BTC flagged as at risk alongside prior confirmed drains of 1,367 BTC. The event heightens custody and operational-risk concerns, may pressure near-term market confidence, and can increase on-chain fee competition as victims attempt to preempt or replace pending attacker transactions via RBF.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT-0.73%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
A possible fourth wave of thefts targeting Bitcoin wallets generated with vulnerable Coldcard devices may already be underway. Blockchain researcher Alex Thorn said on August 3 that nearly 449 BTC had been swept from hundreds of addresses in roughly two and a half hours.
Thorn reported spotting 218 transactions touching 462 suspected victim addresses between Bitcoin blocks 960778 and 969792. The transfers moved 388.93 BTC—about $24.4 million at current prices—into 216 destination addresses that were almost all newly created and showed no prior transaction history.
"These are LIKELY Coldcard victims — they match the shape of coldcard vulnerable utxos and the elevated transaction pattern gives me high confidence they are another wave of attack," Thorn wrote, adding that he had not yet received direct confirmation from victims and used "likely" deliberately.
He later revised the destination list, removing six addresses that had been receiving and spending BTC well before the Coldcard incident began on July 30. Those six addresses accounted for a little over 5 BTC of his earlier total. Thorn also removed 89 multisig addresses, noting none appeared in the first three waves. After the adjustments, he put the core exposure at 709 addresses and 448.73 BTC (about $28.1 million) across confirmed and still-pending transactions.
Thorn urged users to move funds off affected Coldcard devices immediately and use higher transaction fees. He also warned that some pending transactions had Replace-by-Fee (RBF) enabled, meaning victims whose transactions remain in the mempool may have a brief opportunity to outbid the attacker and recover funds before confirmation.
Galaxy Research previously estimated that the first three confirmed waves drained 1,367 BTC—about $85.7 million—from 4,585 Bitcoin addresses. The firm said those funds have not been spent and remain in attacker-controlled wallets, pointing to a coordinated operation rather than opportunistic theft.
Not all stolen BTC has remained untouched. One victim who held close to 30 BTC reportedly saw 17 BTC routed through ThorChain into the Duel online casino; the casino allegedly told the victim to file a police report before it would consider freezing funds.
The incident traces back to a weakness affecting seeds generated on certain Coldcard firmware versions released after March 2021. Coinkite, Coldcard's manufacturer, said seeds created on affected Mk3, Mk4, Mk5 and Q devices are exposed. While patched firmware prevents the issue for newly generated seeds, it cannot secure previously created ones.
Coinkite said it has destroyed remaining vulnerable inventory, paused shipments, and is working with customers and law enforcement to identify those responsible. The company advised users to migrate immediately to a new seed on an unaffected device. Thorn added that every single-signature Coldcard address generated under the vulnerable conditions will eventually be drained.