Coldcard Users Hit by Suspected Fourth Coordinated Attack Wave
Galaxy Research has identified what it believes may be a fourth coordinated attack wave targeting users of Coldcard hardware wallets. The firm's head of research, Alex Thorn, said that between Bitcoin blocks 960,778 and 960,792, attackers moved approximately 388.9 BTC through 218 transactions involving 462 victim addresses and 216 newly created destination addresses.
Transaction activity during the period was about 45 times higher than the level observed before the incident, with some of the Bitcoin already transferred to second-hop addresses. Similar transactions remain pending in the Bitcoin mempool, and confirmed transfers indicate Replace-by-Fee (RBF) opt-in, potentially allowing eligible users to replace pending transactions by broadcasting higher-fee alternatives.
Galaxy Research urged affected users to move funds from Coldcard devices immediately and use higher transaction fees whenever feasible to improve the chances of securing their Bitcoin. The latest activity follows three previously identified suspected attack waves involving Coldcard-generated addresses, which affected 4,585 addresses and resulted in the theft of 1,367.05 BTC, valued at approximately $88.6 million.
Coldcard said it has halted shipments and destroyed all remaining devices running the vulnerable firmware. The company added that Opendime, Satscard, and Tapsigner are not affected. It also stated that patched firmware protects newly generated wallet seeds, but users whose seeds were created using the vulnerable firmware must generate a new seed and transfer their funds.