Fourth attack wave on Coldcard wallets: nearly 449 Bitcoin stolen
Users of Coldcard hardware wallets are once again being hit by an organised attack. Alex Thorn, head of research at Galaxy Research, reports that a suspected fourth wave of attacks is underway in which nearly 449 Bitcoin is disappearing from vulnerable addresses. Users are urgently advised to move their funds immediately.
Bitcoin is available at OKX and Bybit.
In brief:
- A suspected fourth wave of attacks is targeting Coldcard wallets with vulnerable firmware, with around 449 Bitcoin having been siphoned off.
- Activity is roughly 45 times higher than normal, with 709 affected addresses after correction of earlier figures.
- Coldcard has halted shipments and destroyed all devices with the vulnerable firmware. Users must create a new seed and move their funds.
Pattern points to organised attack
Thorn discovered the pattern in blocks 960,778 to 960,792, a period of about two and a half hours. In that time, he found 218 transactions from hundreds of addresses, with the funds being forwarded to new destination addresses. Notably, none of the transactions involved contain inputs from before the vulnerable Coldcard firmware, which strongly suggests that these are victims of precisely that firmware.
The transaction rate is 13.8 sweeps per block, whereas it is normally only 0.3 per block. That amounts to an activity level roughly 45 times higher than usual. Some of the funds have already been forwarded to so-called second-hop addresses, making recovery more difficult.
Corrected figures after initial report
In a later update, Thorn adjusted his figures. His initial analysis erroneously also included multisignature addresses, even though these did not appear in earlier attack waves. After removing those addresses, the final figures come to 709 affected addresses and 448.73 Bitcoin. That is lower than the initially reported 857 addresses and 486.11 Bitcoin.
Thorn says he has not yet received any direct reports from victims of this fourth wave and that his conclusions are based on pattern recognition. He calls on anyone who recognises themselves as a victim to contact him. Similar transactions are still in the mempool awaiting confirmation. Transactions that support RBF may offer an escape route: by submitting a replacement transaction with a higher fee, users can still send their funds to a safe address.
Coldcard halts shipments and calls for action
The three earlier attack waves affected 4,585 addresses and drained 1,367 Bitcoin, then worth approximately $88.6 million. At the current price of $62K, the damage from the fourth wave alone runs into the tens of millions of dollars.
Coldcard has announced that it has stopped shipping devices and destroyed all remaining units with the vulnerable firmware. The Satscard, Opendime and Tapsigner products are not affected. A firmware update offers protection for newly created seeds, but users who ever created a seed on the vulnerable version must generate a completely new seed and move their funds from the old addresses. Anyone who has not yet acted would be well advised to do so as soon as possible.
Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.
Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.