Coldcard wallet losses may near $114 million as possible fourth sweep emerges
A fourth wave of attacks targeting Bitcoin held in Coldcard-generated addresses is ongoing, with an estimated 1,816 BTC (around $114 million) moved from over 5,200 addresses since July 30. Unlike previous waves, these transactions use replace-by-fee, offering victims a ch…
Intelligence analysis by Gemini 2.5 Flash

A critical flaw in Coldcard's 2021 firmware, which used a predictable software randomizer for seed generation, has led to a series of Bitcoin wallet sweeps. The latest wave, potentially bringing total losses to $114 million, utilizes a replace-by-fee mechanism, giving affected users a narrow window to secure their funds by paying higher transaction fees.
Imagine your secret piggy bank code was accidentally made using a simple pattern instead of truly random numbers. Someone figured out the pattern and is now trying to take money from many piggy banks. Luckily, for some, if you see them trying to take your money, you can quickly pay a little extra to move your money to a new, safe piggy bank before they do.
Analysis
The Predictable Seed Flaw
The root cause of the ongoing Coldcard wallet exploit traces back to a critical flaw introduced in a March 2021 firmware build. Instead of utilizing the secure hardware randomizer within the device's chip, this particular firmware version inadvertently routed seed generation to a predictable software randomizer. This oversight meant that the resulting cryptographic keys were no longer truly random and could, in theory, be reproduced offline by anyone capable of discerning the underlying pattern or range. This fundamental vulnerability laid the groundwork for the subsequent waves of attacks, compromising the very foundation of security that hardware wallets are designed to provide.
The initial waves of the attack began on July 30, with the first sweep rapidly siphoning 1,083 Bitcoin from 1,196 addresses in a mere 41 minutes. Two additional waves followed over the weekend, escalating the observed losses to 1,367 Bitcoin across 4,585 addresses. These early attacks demonstrated the attacker's ability to systematically identify and drain funds from compromised wallets, highlighting the severity of the firmware flaw and the extensive reach of the vulnerability across the Coldcard user base who had generated seeds during the affected period.
The Fourth Wave and Replace-by-Fee
A fourth wave of sweeps commenced early Monday, continuing for hours and significantly increasing the total estimated losses. Researchers, including Alex Thorn from Galaxy Research, flagged this active wave, noting a crucial difference: the attackers opted into Bitcoin's replace-by-fee (RBF) feature. This mechanism allows a pending transaction to be overwritten by a new one that pays a higher transaction fee, effectively letting a faster, more expensive transaction confirm first. This means that if a victim spots their funds in the mempool – Bitcoin's queue of unconfirmed transactions – they have a narrow window of opportunity to pay a higher fee and move their coins to a new, secure address before the attacker's transaction confirms.
If this fourth wave holds, the cumulative losses across all four waves are projected to reach approximately 1,816 Bitcoin, valued at nearly $114 million, affecting over 5,200 addresses since July 30. Thorn advised users to immediately check their funds, move any assets off an affected device, and utilize the RBF option by bidding up the transaction fee if their funds are seen in the mempool. This unique aspect of the latest attack provides a glimmer of hope for some victims, offering a last-ditch effort to salvage their assets from the ongoing exploit.
Implications for Coldcard Users and Hardware Wallet Security
The pattern of the attacks strongly suggests that the flaw primarily affects single-key Coldcard seeds, with multisignature setups appearing to be immune. This distinction is critical for users to understand, as it helps identify who might be at risk. Coldcard manufacturer Coinkite has already responded to the vulnerability by releasing emergency firmware updates for all affected models. Furthermore, the company has explicitly advised users who generated their seeds using the flawed software to promptly transfer their funds to a new wallet address created with a freshly generated, secure seed.
This incident serves as a stark reminder that even highly regarded hardware wallets, often considered the pinnacle of self-custody security, are not entirely immune to software vulnerabilities. It underscores the paramount importance of diligent firmware updates, the necessity for users to verify the integrity of their seed generation processes, and the critical need for swift action upon receiving security alerts from manufacturers or researchers. The Coldcard exploit highlights the continuous cat-and-mouse game between security developers and malicious actors in the crypto space, emphasizing that even "cold" storage requires ongoing vigilance and adherence to best practices to remain truly secure.
Key points
- A fourth wave of attacks on Coldcard-generated Bitcoin addresses is underway, potentially bringing total losses to $114 million.
- The exploit stems from a March 2021 firmware flaw that used a predictable software randomizer for seed generation.
- The latest transactions utilize Bitcoin's replace-by-fee (RBF) feature, allowing victims to potentially move their funds first by paying a higher fee.
- The flaw appears to affect single-key Coldcard seeds, not multisignature setups.
- Coldcard manufacturer Coinkite released emergency firmware and advised affected users to move funds.
The use of replace-by-fee in the latest attack wave offers a narrow window for victims to potentially save their funds by outbidding the attacker, mitigating some of the potential losses. This incident also serves as a critical reminder for users to update firmware and verify their seed generation methods, potentially leading to enhanced security practices across the ecosystem.
Despite the replace-by-fee option, many victims may not be aware or quick enough to react, leading to significant irreversible losses of Bitcoin. The exploit of a hardware wallet, often considered the gold standard for security, could erode user trust in such devices and the broader crypto ecosystem.



