Coldcard wallet losses hit $114M as fourth sweep emerges
In brief
- Fourth Coldcard sweep began Monday, adding to 1,367 bitcoin stolen over the weekend across prior waves.
- Attackers used replace-by-fee to enable victims a window to outbid and move coins first.
- Root cause: March 2021 firmware routed seed generation to predictable software randomness instead of hardware randomizer.
- Coinkite released emergency firmware for all affected Coldcard models.
- Latest wave targeted 462 victim addresses at 45× normal sweep rate across 218 transactions.
The Exploit Window
The timing matters. A victim who finds their address in the mempool can pay more and move the coins out first. The attackers didn't use absolute lock-in; they left the door cracked. That's unusual for theft at this scale, and it signals either operational sloppiness or a deliberate choice to let some victims escape. Either way, anyone watching the mempool closely has minutes to act.
The first attack wave on July 30 took 1,083 bitcoin from 1,196 addresses in 41 minutes. Two further waves over the weekend brought observed losses to 1,367 bitcoin across 4,585 addresses. The fourth wave escalated the pattern again.
Root Cause: Predictable Randomness
The flaw traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the chip's hardware one. The resulting keys were reproducible offline by anyone who works out the range. That's the catastrophic failure: a hardware wallet that generates keys in software, predictably, defeats the entire premise of cold storage.
Coinkite released emergency firmware for every affected model. Users who haven't patched are still vulnerable.
Pattern Analysis and Attribution
Alex Thorn, head of firmwide research at Galaxy Research, flagged the active wave. Thorn had no direct victim report and published his findings on pattern matching alone. The pattern covered blocks 960,778 to 960,792, with 218 transactions hitting 462 victim addresses.
The sweep rate was about 14 sweeps per block against 0.3 in a pre-incident control window, roughly 45 times normal. The spike is unmistakable. Spent coins that arrived after the Coldcard firmware boundary had destinations that were fresh addresses with no prior history, further isolating the victim set.
One detail stands out: None of the first three waves touched multisignature setups. The attacker knows the vulnerability's limits and stays within them. That's not random noise. That's precision.


