discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Coldcard wallet losses may near $114 million as possible fourth sweep emerges

A fourth wave of attacks targeting Bitcoin held in Coldcard-generated addresses is ongoing, with an estimated 1,816 BTC (around $114 million) moved from over 5,200 addresses since July 30. Unlike previous waves, these transactions use replace-by-fee, offering victims a ch…

By Shaurya Malwa·Aug 3·coindesk.com·4 min read

Intelligence analysis by Gemini 2.5 Flash

CoinDesk
CoinDeskImage: coindesk.com

A critical flaw in Coldcard's 2021 firmware, which used a predictable software randomizer for seed generation, has led to a series of Bitcoin wallet sweeps. The latest wave, potentially bringing total losses to $114 million, utilizes a replace-by-fee mechanism, giving affected users a narrow window to secure their funds by paying higher transaction fees.

Why it matters

This incident highlights significant security vulnerabilities in hardware wallets, even those considered highly secure, and underscores the importance of vigilant firmware updates and understanding the underlying technology for crypto users.

Imagine your secret piggy bank code was accidentally made using a simple pattern instead of truly random numbers. Someone figured out the pattern and is now trying to take money from many piggy banks. Luckily, for some, if you see them trying to take your money, you can quickly pay a little extra to move your money to a new, safe piggy bank before they do.

Analysis

The Predictable Seed Flaw

The root cause of the ongoing Coldcard wallet exploit traces back to a critical flaw introduced in a March 2021 firmware build. Instead of utilizing the secure hardware randomizer within the device's chip, this particular firmware version inadvertently routed seed generation to a predictable software randomizer. This oversight meant that the resulting cryptographic keys were no longer truly random and could, in theory, be reproduced offline by anyone capable of discerning the underlying pattern or range. This fundamental vulnerability laid the groundwork for the subsequent waves of attacks, compromising the very foundation of security that hardware wallets are designed to provide.

The initial waves of the attack began on July 30, with the first sweep rapidly siphoning 1,083 Bitcoin from 1,196 addresses in a mere 41 minutes. Two additional waves followed over the weekend, escalating the observed losses to 1,367 Bitcoin across 4,585 addresses. These early attacks demonstrated the attacker's ability to systematically identify and drain funds from compromised wallets, highlighting the severity of the firmware flaw and the extensive reach of the vulnerability across the Coldcard user base who had generated seeds during the affected period.

The Fourth Wave and Replace-by-Fee

A fourth wave of sweeps commenced early Monday, continuing for hours and significantly increasing the total estimated losses. Researchers, including Alex Thorn from Galaxy Research, flagged this active wave, noting a crucial difference: the attackers opted into Bitcoin's replace-by-fee (RBF) feature. This mechanism allows a pending transaction to be overwritten by a new one that pays a higher transaction fee, effectively letting a faster, more expensive transaction confirm first. This means that if a victim spots their funds in the mempool – Bitcoin's queue of unconfirmed transactions – they have a narrow window of opportunity to pay a higher fee and move their coins to a new, secure address before the attacker's transaction confirms.

If this fourth wave holds, the cumulative losses across all four waves are projected to reach approximately 1,816 Bitcoin, valued at nearly $114 million, affecting over 5,200 addresses since July 30. Thorn advised users to immediately check their funds, move any assets off an affected device, and utilize the RBF option by bidding up the transaction fee if their funds are seen in the mempool. This unique aspect of the latest attack provides a glimmer of hope for some victims, offering a last-ditch effort to salvage their assets from the ongoing exploit.

Implications for Coldcard Users and Hardware Wallet Security

The pattern of the attacks strongly suggests that the flaw primarily affects single-key Coldcard seeds, with multisignature setups appearing to be immune. This distinction is critical for users to understand, as it helps identify who might be at risk. Coldcard manufacturer Coinkite has already responded to the vulnerability by releasing emergency firmware updates for all affected models. Furthermore, the company has explicitly advised users who generated their seeds using the flawed software to promptly transfer their funds to a new wallet address created with a freshly generated, secure seed.

This incident serves as a stark reminder that even highly regarded hardware wallets, often considered the pinnacle of self-custody security, are not entirely immune to software vulnerabilities. It underscores the paramount importance of diligent firmware updates, the necessity for users to verify the integrity of their seed generation processes, and the critical need for swift action upon receiving security alerts from manufacturers or researchers. The Coldcard exploit highlights the continuous cat-and-mouse game between security developers and malicious actors in the crypto space, emphasizing that even "cold" storage requires ongoing vigilance and adherence to best practices to remain truly secure.

Key points

  • A fourth wave of attacks on Coldcard-generated Bitcoin addresses is underway, potentially bringing total losses to $114 million.
  • The exploit stems from a March 2021 firmware flaw that used a predictable software randomizer for seed generation.
  • The latest transactions utilize Bitcoin's replace-by-fee (RBF) feature, allowing victims to potentially move their funds first by paying a higher fee.
  • The flaw appears to affect single-key Coldcard seeds, not multisignature setups.
  • Coldcard manufacturer Coinkite released emergency firmware and advised affected users to move funds.
The Upside

The use of replace-by-fee in the latest attack wave offers a narrow window for victims to potentially save their funds by outbidding the attacker, mitigating some of the potential losses. This incident also serves as a critical reminder for users to update firmware and verify their seed generation methods, potentially leading to enhanced security practices across the ecosystem.

The Downside

Despite the replace-by-fee option, many victims may not be aware or quick enough to react, leading to significant irreversible losses of Bitcoin. The exploit of a hardware wallet, often considered the gold standard for security, could erode user trust in such devices and the broader crypto ecosystem.

Originally reported at

coindesk.com

Discernion covers the story. Read the full piece at the source.

Tagscryptosecurityhardware-walletbitcoinexploitvulnerability

Author

Shaurya Malwa

Intelligence analysis by

Gemini 2.5 Flash

Published

Aug 3, 2026

Source

coindesk.com

Share

Topics

cryptosecurityhardware-walletbitcoinexploitvulnerability

Related

More from this desk

Aug 3·cointelegraph.com

HashKey receives JPMorgan approval to open client money account

Hong Kong-licensed cryptocurrency exchange HashKey Exchange has secured approval from JPMorgan Chase to open a client money account, enhancing its banking infrastructure for segregated client funds.

Aug 3·cointelegraph.com

Bitget to exit Japan, close remaining positions after Dec. 31

Crypto exchange Bitget is ceasing services for residents of Japan, halting new registrations immediately and progressively restricting existing accounts from November 1, with all open positions forcibly closed by December 31.

A mug of black coffee, leather notebook, glasses and pen rest on top of spreadsheet printout.
Aug 3·coindesk.com

U.S. Jobs, Circle, Galaxy, American Bitcoin earnings: Crypto Week Ahead

The upcoming week for crypto markets is shaped by the U.S. jobs report, which could influence Federal Reserve policy, alongside earnings from major crypto firms like Circle and Galaxy, and significant blockchain protocol developments.

CoinDesk
Aug 3·coindesk.com

Bitcoin slips under $63,000 despite Iran deal hopes as Coldcard losses rattle market

Major cryptocurrencies, including Bitcoin and Ether, fell despite improving macro conditions, as a widening exploit of Coldcard hardware wallets drained nearly $89 million from thousands of addresses.