Attackers began a fourth wave of sweeps against bitcoin held in Coldcard hardware wallets on Monday, pushing estimated losses to roughly $114 million since Thursday. The latest transactions remained replaceable in the mempool, giving some victims a brief window to move their coins before the thefts confirm.
The thefts stem from a firmware bug that shipped in March 2021 and went unnoticed for more than five years, undercutting the core promise of hardware wallets: that keys generated on the device cannot be guessed. Coldcard maker Coinkite has released emergency firmware for every affected model, halted shipments, and told users to move funds to freshly generated seeds.
Alex Thorn, head of firmwide research at Galaxy, flagged the new wave early Monday, counting 448.7 BTC swept from 709 potential victim addresses at a rate of 13.8 sweeps per block — about 45 times the rate in a pre-incident control window. That comes on top of the 1,367 BTC taken from 4,585 addresses across three earlier waves, bringing the estimated total to about 1,816 BTC from more than 5,200 addresses.
"These are LIKELY Coldcard victims — they match the shape of coldcard vulnerable utxos and the elevated transaction pattern gives me high confidence they are another wave of attacks," Thorn wrote.










