NextFin

Coldcard Wallet Losses Near $114 Million as a Fourth Sweep Emerges

Summarized by NextFin AI
  • Researchers estimate Coldcard-related Bitcoin losses have risen to about 1,816 BTC, roughly $114 million, as a suspected fourth wave continues sweeping vulnerable wallets rather than ending as a one-time theft.
  • The latest wave may have affected hundreds of additional addresses, with some transactions still unconfirmed in the mempool, creating a brief chance for victims to use replace-by-fee (RBF) to outbid the attacker.
  • The root cause appears to be a March 2021 firmware seed-generation flaw that used a deterministic software pseudorandom number generator instead of the device's hardware random generator, making old wallet seeds structurally vulnerable.
  • Bitcoin held near $62,500 despite the incident, suggesting markets view this as a hardware-wallet security failure rather than a Bitcoin protocol break, though it could still drive users to migrate funds and reassess self-custody.

NextFin News - A suspected fourth wave of sweeps against Coldcard-generated Bitcoin addresses has pushed the running loss estimate to about 1,816 BTC, or roughly $114 million, and the episode is now looking less like a single theft than a continuing exposure of wallets created on vulnerable firmware. Researchers say the activity began July 30, and the latest wave appears to have hit hundreds of additional addresses while some transactions still sat unconfirmed in the mempool, creating a narrow chance for users to outbid the attacker with replace-by-fee if they reacted fast enough.

That detail matters because it changes the incident from a post-loss forensic story into a live race. Earlier waves moved quickly through obvious targets. The newest wave appears to leave some room for intervention before confirmation, which means the issue is not only how much bitcoin has been stolen, but how many vulnerable wallets are still out there and whether their owners know it in time.

The market has responded with unusual restraint. Bitcoin was trading around $62,500 as the fourth-wave reports circulated, down only modestly on the day. That muted reaction suggests traders are treating the event as a concentrated hardware-wallet failure rather than a protocol-level break in Bitcoin itself. The larger implication may be behavioral: holders who believe their seed was generated on affected firmware may move funds into fresh wallets, onto new devices, or in some cases back to exchange custody as a temporary stopgap.

The scale of the attack has grown in stages. The first sweep drained 1,082.65 BTC from 1,196 addresses in 41 minutes. Later waves lifted the observed total to 1,367.05 BTC across 4,585 addresses. The current estimate near 1,816 BTC suggests the attacker has continued to find exposed balances as researchers refine address clusters and as more wallets are identified. The episode is no longer just a question of stolen coins. It is a question of how large the remaining vulnerable set still is.

Several numbers now frame the broader stress. One clustering pass on the fourth wave put it at 709 addresses and 448.73 BTC, about $28 million. Another public scan described 218 transactions hitting 462 victim addresses and 216 fresh destinations across blocks 960,778 to 960,792, with activity running at about 45 times the pre-incident baseline. The exact fourth-wave count may shift as the analysis window changes, but both versions point in the same direction: the attacker is still finding usable Coldcard-derived wallets inside the same exposed population.

What Actually Broke?

The core failure appears to be in seed generation, not in a live compromise of the device. Researchers tied the problem to a March 2021 firmware integration error that routed seed creation to a deterministic software pseudorandom number generator instead of the hardware random number generator inside the device. That is a narrow technical detail with large consequences. A hardware wallet can stay offline and still fail if the seed at the center of the wallet was not truly random in the first place.

That is why the attack is so unnerving. It bypasses the usual threat model. There is no malware on the user’s computer, no phishing page asking for a recovery phrase, and no need to touch the wallet physically. If the seed was created on affected firmware, the weakness lives at the start of the wallet’s life cycle, and the fact that the device later stored keys offline does not repair that origin flaw.

The first wave exposed the scale. The later waves exposed the persistence. The latest wave shows the problem is still being mapped in real time. That makes this a structural issue, not a cyclical one. A cyclical problem fades when conditions change. A structural problem stays until every affected wallet is remediated. This one is structural because the risk is embedded in old seeds and cannot be reversed by waiting.

The attack also appears to favor single-signature wallets rather than multisignature setups. That distinction matters because it narrows the practical exposure: the flaw affects Coldcard-generated seeds, but not every setup built with the brand. Still, the existence of a vulnerable single-key universe is enough to keep the story open, because the attacker only needs to find one weak seed while each victim must secure every old one that exists.

“There are still similar txs in the mempool waiting to be confirmed and the previously-confirmed txs signal RBF opt-in,” Alex Thorn wrote, adding that users may be able to “RBF your way out of this” if they move quickly.

That warning captures the incident’s new mechanics. Replace-by-fee turns some sweeps into a contest over confirmation. If a victim spots a pending sweep and the transaction has opted in to RBF, a higher fee can sometimes win the race. Once confirmed, the window closes. The attacker is no longer just draining wallets; in some cases, they are forcing owners into a fee-bidding duel to save what remains.

Why The Fourth Wave Changes The Story

The fourth wave matters because it suggests the incident is still expanding rather than simply being counted. Analysts first treated this as a large theft, then as a cluster of related thefts, and now as a rolling campaign against the same vulnerable address generation path. That is the signature of a seed problem, not a one-off event. Once the key space is identified, the discovery process itself becomes part of the loss path.

The pace is also notable. The latest wave was described as running across 15 consecutive blocks, about 45 times the normal sweep rate. One estimate put it at 709 addresses and 448.73 BTC, while another pointed to 218 transactions hitting 462 victim addresses and 216 fresh destinations. The precise count matters less than the direction: the attacker is still finding balances that had not yet been captured, even after the original waves and the first rounds of public warnings.

That creates a second-order effect the market may be underpricing. The first-order effect is the lost bitcoin. The second-order effect is the behavioral shift: users re-evaluating self-custody, wallets being moved to fresh seeds, and some holders temporarily shifting to exchange or third-party custody while they sort out whether their original setup is safe. If the incident triggers that kind of migration, the impact extends beyond the stolen coins themselves.

There is also a practical asymmetry in the attacker’s favor. The attacker needs only a subset of exposed wallets to keep finding value. The victim has to verify provenance for every seed created on the vulnerable code path. That makes the problem lopsided. The more time passes, the more likely it is that dormant wallets get rediscovered, because time does not make a weak seed stronger.

Is This Cyclical Or Structural?

This is structural, not cyclical. The sweep count is cyclical only in the narrow sense that the theft arrives in bursts. The underlying security failure does not mean-revert. It is not a temporary liquidity event, and it is not the sort of market stress that naturally fades once leverage is flushed out. It is a persistent vulnerability in a past firmware path that remains dangerous until users rebuild their wallets from fresh seeds.

The evidence for that call is straightforward. First, the root cause is technical and permanent: a seed-generation flaw tied to a specific firmware era. Second, the risk is stateful, not transient: once a seed is created on vulnerable firmware, it remains exposed. Third, the remedy is manual and individualized: each affected holder has to generate a new seed and move funds. Those are structural features, not cyclical ones.

The strongest counter-thesis is that the market is overreading a finite security event. On that view, the main damage happened in the first wave, the remaining pool is smaller than feared, and Bitcoin itself is showing that it can absorb the shock because the price reaction has stayed muted. That argument is not trivial. It is plausible that the attacker is mostly working through a pre-defined address set and that the fourth wave simply reflects better clustering, not a genuinely larger exposure.

But that counter-thesis only holds if the remaining clusters dry up. The falsifying signal for the structural view is concrete: if the cumulative total stops rising and no fresh wallet clusters appear after the current roughly 1,816 BTC estimate, then the incident starts to look bounded. If instead new sweeps keep appearing and the total moves materially higher, the case for a continuing structural remediation problem becomes stronger.

The second-order issue is even more important than the direct theft. The market may already have priced a headline loss. What it may not fully price is the longer migration away from affected self-custody setups. That is where the incident could still matter after the initial shock has passed.

What Comes Next?

In the short term, the question is whether any pending transactions remain eligible for replace-by-fee. If they do, some owners may still be able to rescue funds by moving faster and paying a higher fee. That is a narrow tactical issue, not a strategic solution. It only helps if the wallet is still in the mempool stage and the user notices in time.

Over the medium term, the beneficiaries are the wallet makers, custodians, and security teams that can prove they use safer entropy generation and cleaner recovery paths. The exposed group is broader: anyone who created a seed on the vulnerable Coldcard firmware path and has not yet migrated funds. The incident also pressures institutions that rely on cold storage to explain what portion of their operational security depends on similar setup assumptions.

Over the long term, the episode is about standards, not just one brand. A hardware wallet is only as safe as the chain from entropy to backup to recovery. If that chain is weak at setup, the device can still fail the user even while it remains offline. That is why this story is bigger than a theft count. It is a reminder that a cold wallet is only cold if the seed is sound.

Base case: the running total rises only modestly from here as users and researchers close the remaining gaps, and the market treats the incident as a painful but contained hardware-wallet failure. Upside case for the attacker: additional dormant addresses surface and the cumulative figure moves well above the current estimate, forcing a broader migration away from affected devices. Downside case: the remaining pool proves smaller than feared, the sweep pace fades, and the event is remembered as a severe but finite security shock.

The lesson is not that bitcoin itself broke. It is that a weak seed can sit quietly for years and still become a live liability the moment someone learns how to look for it. Once that happens, the clock is no longer on the chain. It is on the wallet owner.

Explore more exclusive insights at nextfin.ai.

Insights

What was the original cause of the vulnerability in Coldcard wallets?

How has the Coldcard wallet attack evolved over its different waves?

What impact has the Coldcard incident had on Bitcoin's market price?

What strategies can users employ to protect their funds during the attack?

What recent updates have been made regarding the Coldcard wallet vulnerabilities?

What are the long-term implications of the Coldcard wallet incident for wallet security standards?

What challenges do users face when verifying the safety of their Coldcard wallets?

How do the Coldcard vulnerabilities compare with other hardware wallet failures?

What behavioral changes have users exhibited in response to the Coldcard incidents?

What technical principles underpin the security of hardware wallets like Coldcard?

What is the potential for future attacks on Coldcard wallets or similar devices?

What are the main controversies surrounding the Coldcard wallet security issues?

How has the industry adjusted its response to hardware wallet vulnerabilities following the Coldcard incident?

What lessons can be drawn from the Coldcard wallet incident for future hardware wallet designs?

How do replace-by-fee mechanisms work in the context of the Coldcard wallet attacks?

What role do custodians and wallet makers play in the aftermath of the Coldcard incident?

What evidence supports the claim that the Coldcard wallet issue is a structural problem?

What is the significance of the fourth wave of attacks on Coldcard wallets?

How can users identify if their Coldcard wallet is affected by the vulnerabilities?

Search
NextFinNextFin
NextFin.Al
No Noise, only Signal.
Open App