Coldcard Hack Hits $116 Million as Fourth Wave Continues Unabated
The Coldcard hardware wallet hack has reached unprecedented levels, with over $116 million stolen in four separate waves. The most recent wave, which occurred on August 3, saw a sweep rate of 45 times the pre-incident baseline, indicating that multiple groups may be racing to exploit vulnerable addresses.
The root cause of the hack is a 2021 firmware update that switched the wallet's seed-generation process from a strong hardware-based randomness source to a predictable software pattern. This means that any wallet seed created on affected devices could be guessed rather than brute-forced, making it easier for attackers to target exposed addresses.
Coldcard manufacturer Coinkite has acknowledged the scale of the damage and advised users to move their funds to a new, safely generated wallet as soon as possible. The company's statement described the last three days as 'some of the hardest in this company's history', and warned that victims have a narrow window to attempt Replace-By-Fee transactions on unconfirmed transfers.
Industry personnel like Anthony Pompliano have pushed back against the narrative that the hack was on Bitcoin itself, arguing that the flaw sat squarely in Coldcard's firmware rather than the BTC protocol.