Coldcard Attack Wave Hits Bitcoin Addresses, $114M At Risk
A new wave of attacks targeting Coldcard-generated Bitcoin addresses has emerged, potentially putting $114 million at risk. The attack began on July 30 and has so far moved about 1,816 Bitcoin from more than 5,200 addresses.
Unlike previous waves, the latest transactions use Bitcoin's replace-by-fee feature, which allows victims to outbid the attacker and move their funds first. This means that users who spot their coins in the mempool may still be able to recover their losses.
Alex Thorn, head of firmwide research at Galaxy Research, flagged the active wave and noted that the attackers opted into replace-by-fee, allowing victims to potentially override the transactions while they sit unconfirmed. Thorn advised users to check their funds, move anything off an affected device, and bid up the fee.
The pattern suggests that the flaw affects single-key Coldcard seeds and not multisignature setups, with the attacker sending funds to previously unused addresses that are harder to trace than in prior waves.