Bitcoin Coldcard Wallets Hit by Fourth Wave of Multi-Million Dollar Attacks
A new wave of attacks against Bitcoin users who store their funds in Coldcard-generated addresses is underway, potentially putting over $114 million at risk. The attacker has moved about 1,816 BTC from more than 5,200 addresses since July 30, with researchers estimating the total losses may near $114 million.
The latest wave of sweeps uses Bitcoin's replace-by-fee feature, which allows victims who spot their coins in the mempool to outbid the attacker and move their funds first. This is a departure from earlier waves, where transactions were not overridden.
Alex Thorn, head of firmwide research at Galaxy Research, flagged the active wave and noted that the attackers opted into replace-by-fee, allowing victims to potentially recover their funds. The flaw affecting single-key Coldcard seeds, but not multisignature setups, was identified in a March 2021 firmware build.
Coldcard manufacturer Coinkite released emergency firmware for affected models and advised users who generated a seed on the flawed software to move funds to a new wallet address. Thorn warned users to check their funds, move anything off an affected device, and bid the fee up to prevent further losses.