Coldcard Under Fire Again: $88.6 Million in BTC at Risk
A fourth wave of organized attacks has been detected targeting users of Coldcard hardware wallets. The attacks put approximately 388.9 Bitcoin at risk, according to Alex Thorn, Head of Research at Galaxy Research. The suspicious transactions occurred between blocks 960,778 and 960,792 on the Bitcoin network, revealing that assets from hundreds of victim addresses were being transferred to new wallets.
The scale of the attack reached a level approximately 45 times higher than normal network activity. Assets were withdrawn from 462 victim addresses via 218 transactions, with some stolen funds already being transferred to second-stage addresses. Experts warn users that funds can be recovered for unconfirmed transactions by using RBF (Replace-by-Fee) to divert the funds back to safety.
This latest incident is recorded as the fourth major wave targeting Coldcard addresses. In previous attacks, 4,585 addresses were affected, and 1,367.05 Bitcoin worth approximately $88.6 million was stolen. Although the company stopped shipping devices with vulnerable firmware and destroyed existing stock, wallets created with old firmware still carry a high risk.
Coldcard users must update their devices to the latest firmware version and create a new seed phrase to move their assets. Other products like Satscard and Opendime are unaffected, but it is crucial to immediately transfer funds from old wallets created with risky firmware to a secure address.