Updated Aug 3, 2026, 9:09 a.m. Published Aug 3, 2026, 8:51 a.m. 2 min readBitcoin cold-wallet losses may near $114 million as possible fourth sweep emerges. (Coldcard/Coinkite)SummaryA fourth wave of sweeps targeting bitcoin in Coldcard-generated addresses is underway, with researchers estimating the attacker has moved about 1,816 bitcoin, or roughly $114 million, from more than 5,200 addresses since July 30.Unlike earlier waves, the latest transactions appear to use bitcoin’s replace-by-fee feature, meaning victims who spot their coins in the mempool may still be able to outbid the attacker and move their funds first.The pattern suggests the flaw affects single-key Coldcard seeds and not multisignature setups, with the attacker sending funds to previously unused addresses that are harder to trace than in prior waves.A fourth wave of sweeps against bitcoin BTC$62,560.27 addresses generated by the Coldcard cold wallet began early Monday and was still running hours later. This time, however, researchers say the transactions can be overridden while they sit unconfirmed.Alex Thorn, head of firmwide research at Galaxy Research, flagged the active wave and said the attackers opted into replace-by-fee, a Bitcoin feature that lets a pending transaction be overwritten by a later one paying a higher fee. Until a transaction confirms, a victim who finds their address in the mempool — the queue of unconfirmed transactions — can pay more and move the coins out first.The attack started July 30 in a sweep that took 1,083 bitcoin from 1,196 addresses in 41 minutes. Two further waves over the weekend brought observed losses to 1,367 bitcoin across 4,585 addresses. The flaw allowing the exploit traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the chip's hardware one, leaving the resulting keys reproducible offline by anyone who works out the range. Coldcard manufacturer Coinkite released emergency firmware for every affected model and told users who had generated a seed on the flawed software to move funds to a wallet address made with a fresh one.Thorn said he had no direct victim report and published his findings on pattern matching alone, choosing speed over confirmation to warn people while the transactions were still unconfirmed.If it holds, however, the running total across four waves had reached about 1,816 bitcoin, near $114 million, from more than 5,200 addresses since July 30.The Coldcard attacker went after dust, then found value again. (Shaurya Malwa/CoinDesk)Thorn advised users to check funds, move anything off an affected device and bid the fee up.The pattern covered blocks 960,778 to 960,792, with 218 transactions hitting 462 victim addresses at a rate of about 14 sweeps per block against 0.3 in a pre-incident control window, roughly 45 times normal. Each of the spent coins that arrived after the Coldcard firmware boundary, and the destinations were fresh addresses with no prior history, one per victim rather than the shared collectors that made the first two waves easy to map.None of the first three waves touched multisignature setups, which is consistent with the flaw affecting single-key seeds. Six destination addresses with years of prior activity also came out, since a freshly generated attacker address cannot have a history.Related Assets12345678910The Evolution of the Crypto CEX Landscape: A Case Study on BinanceThe Evolution of the Crypto CEX Landscape: A Case Study on BinanceBinance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.Jun 29, 2026Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.Why it matters:Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.View Full Report
Coldcard wallet losses may near $114 million as possible fourth sweep emerges
The pending transactions signal replace-by-fee, so anyone who spots their address in the mempool has minutes to pay a higher fee and move funds first.

The pending transactions signal replace-by-fee, so anyone who spots their address in the mempool has minutes to pay a higher fee and move funds first.
- Until a transaction confirms, a victim who finds their address in the mempool — the queue of unconfirmed transactions — can pay more and move the coins out first.The attack started July 30 in a sweep that took 1,083 bitcoin from 1,196 addresses in 41 minutes.
- Two further waves over the weekend brought observed losses to 1,367 bitcoin across 4,585 addresses.
- The flaw allowing the exploit traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the chip's hardware one, leaving the resulting keys reproducible offline by anyone who works out the range.
What people are saying
Hot takes
Loading takes…
Comments
Discussion · 0
Sign in to comment, like, and save articles.
Sign inLoading comments…




