Crypto & Web3·Aug 3, 2026

Coldcard wallet losses may near $114 million as possible fourth sweep emerges

The pending transactions signal replace-by-fee, so anyone who spots their address in the mempool has minutes to pay a higher fee and move funds first.

CoinDesk3 min readVerified
Coldcard wallet losses may near $114 million as possible fourth sweep emerges
Image · CoinDesk
The gist
3-point summary · 1 min

The pending transactions signal replace-by-fee, so anyone who spots their address in the mempool has minutes to pay a higher fee and move funds first.

  • Until a transaction confirms, a victim who finds their address in the mempool — the queue of unconfirmed transactions — can pay more and move the coins out first.The attack started July 30 in a sweep that took 1,083 bitcoin from 1,196 addresses in 41 minutes.
  • Two further waves over the weekend brought observed losses to 1,367 bitcoin across 4,585 addresses.
  • The flaw allowing the exploit traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the chip's hardware one, leaving the resulting keys reproducible offline by anyone who works out the range.
$114 million$62,560.27March 2021
In this article

Updated Aug 3, 2026, 9:09 a.m. Published Aug 3, 2026, 8:51 a.m. 2 min readBitcoin cold-wallet losses may near $114 million as possible fourth sweep emerges. (Coldcard/Coinkite)SummaryA fourth wave of sweeps targeting bitcoin in Coldcard-generated addresses is underway, with researchers estimating the attacker has moved about 1,816 bitcoin, or roughly $114 million, from more than 5,200 addresses since July 30.Unlike earlier waves, the latest transactions appear to use bitcoin’s replace-by-fee feature, meaning victims who spot their coins in the mempool may still be able to outbid the attacker and move their funds first.The pattern suggests the flaw affects single-key Coldcard seeds and not multisignature setups, with the attacker sending funds to previously unused addresses that are harder to trace than in prior waves.A fourth wave of sweeps against bitcoin BTC$62,560.27 addresses generated by the Coldcard cold wallet began early Monday and was still running hours later. This time, however, researchers say the transactions can be overridden while they sit unconfirmed.Alex Thorn, head of firmwide research at Galaxy Research, flagged the active wave and said the attackers opted into replace-by-fee, a Bitcoin feature that lets a pending transaction be overwritten by a later one paying a higher fee. Until a transaction confirms, a victim who finds their address in the mempool — the queue of unconfirmed transactions — can pay more and move the coins out first.The attack started July 30 in a sweep that took 1,083 bitcoin from 1,196 addresses in 41 minutes. Two further waves over the weekend brought observed losses to 1,367 bitcoin across 4,585 addresses. The flaw allowing the exploit traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the chip's hardware one, leaving the resulting keys reproducible offline by anyone who works out the range. Coldcard manufacturer Coinkite released emergency firmware for every affected model and told users who had generated a seed on the flawed software to move funds to a wallet address made with a fresh one.Thorn said he had no direct victim report and published his findings on pattern matching alone, choosing speed over confirmation to warn people while the transactions were still unconfirmed.If it holds, however, the running total across four waves had reached about 1,816 bitcoin, near $114 million, from more than 5,200 addresses since July 30.The Coldcard attacker went after dust, then found value again. (Shaurya Malwa/CoinDesk)Thorn advised users to check funds, move anything off an affected device and bid the fee up.The pattern covered blocks 960,778 to 960,792, with 218 transactions hitting 462 victim addresses at a rate of about 14 sweeps per block against 0.3 in a pre-incident control window, roughly 45 times normal. Each of the spent coins that arrived after the Coldcard firmware boundary, and the destinations were fresh addresses with no prior history, one per victim rather than the shared collectors that made the first two waves easy to map.None of the first three waves touched multisignature setups, which is consistent with the flaw affecting single-key seeds. Six destination addresses with years of prior activity also came out, since a freshly generated attacker address cannot have a history.Related Assets12345678910The Evolution of the Crypto CEX Landscape: A Case Study on BinanceThe Evolution of the Crypto CEX Landscape: A Case Study on BinanceBinance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.Jun 29, 2026Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.Why it matters:Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.View Full Report

Integrity note  ·  Xela does not rewrite or paraphrase article content. The excerpt above is the source publication's own words, sanitized for display. For the full piece — including any quotes, charts, or images — read it at CoinDesk. Xela's rewritten version is off for this story, so there's no editorial angle attached — you're getting the source's reporting unfiltered. When the rewrite is on, we add a What this means block underneath with the operator/trader takeaway.

What people are saying

Discussion

Hot takes

0/280

Loading takes…

Comments

Discussion · 0

Sign in to comment, like, and save articles.

Sign in

Loading comments…

Newsletter

Track crypto & web3 every morning.

Daily digest tuned to this beat. The 5 stories most worth your time. Unsubscribe anytime.