Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    July Crypto Stock Breakdown Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    July Crypto Stock Breakdown: Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    What Happens If the CLARITY Act Does Not Pass?
    What Happens If the CLARITY Act Does Not Pass?
    The Trump Crypto Presidency Power, Policy, and $1.4 Billion
    The Donald Trump Crypto Presidency: Power, Policy, and $2.3 Billion
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    GENIUS Deadline Missed, CLARITY Act Stalls on Ethics: USA’s 2 Crypto Laws Stuck
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
    2 Years of the ₹2,000 Cr WazirX Hack: The Money Never Came Back. Neither Did the Founder
  • Opinion
    OpinionShow More
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Bitcoin Treasury Blueprint What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    The Bitcoin Treasury Blueprint: What Stress Testing on Strategy Inc.’s MSTR-STRC Reveals
    Why Wall Street is Divided Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    Why Wall Street is Divided: Michael Saylor’s Scarcity vs. Tom Lee’s Staking Empire
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Bitcoin News

Coldcard Hack Enters Wave 4: 449 BTC Swept Live as Victims Race to Save Funds

Galaxy Research found Wave 4 moved 388.93 BTC across 218 transactions from 462 vulnerable Coldcard addresses, with on-chain patterns suggesting multiple coordinated attackers exploiting the same firmware flaw simultaneously.

Written By Dishita Malvania
Edited by Divya Mistry
Published 1 hour ago·Updated 50 minutes ago
Make The Crypto Times preferred on GoogleGoogle
Coldcard Hack Enters Wave 4 449 BTC Swept Live as Victims Race to Save Funds
AI Summary
Show
A firmware flaw in Coldcard hardware wallets has led to a series of thefts, with the root cause remaining unpatched for existing seeds, allowing attackers to exploit vulnerable key sets.
The wave 4 thefts demonstrate a coordinated effort, with a sweep rate 45 times higher than the baseline, and a topology that suggests multiple groups are racing to exploit the Coldcard key space.
The root cause of the issue dates back to a March 2021 code commit, which silently rerouted seed generation, resulting in reduced entropy and permanently compromised seeds, highlighting a need for improved security measures.

Galaxy Research’s Alex Thorn has flagged what he described as a probable fourth organized wave of thefts targeting Coldcard hardware wallet users, warning on X on August 3 that the sweep was still in motion inside the mempool at the time of his post. Unlike the previous three waves, which were dissected only after the fact, wave 4 was called out while affected users still had a technical route to save their coins.

The head of firmwide research at Galaxy Digital said the confirmed portion of the sweep had already moved 388.93 BTC across 218 transactions from 462 victim addresses to 216 freshly created destinations, all landing in blocks 960,778 through 960,792 over a rolling window of roughly two and a half hours. 

🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW

THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS

pattern identified:
blocks…

— Alex Thorn (@intangiblecoins) August 3, 2026

Every one of those inputs sat on the wrong side of the March 2021 Coldcard firmware boundary, the same regression that has powered every wave since July 30.

Rate spike and topology point to another coordinated operator

For an analyst, the numbers behind wave 4 matter less than their shape. Thorn measured the sweep rate at 13.8 transfers per block against a pre-incident control window of 0.3 per block, an elevation of roughly 45 times baseline. That kind of clustering is not a run of bad luck. It is the fingerprint of an automated pipeline chewing through a pre-computed list of vulnerable keys against a live mempool.

The topology matters just as much. Every victim in the confirmed set was routed to its own fresh destination address in a strict one-to-one mapping, and only a single destination received two sweeps. There is no collector wallet funneling coins into a consolidation point, which sets wave 4 apart from wave 1 and wave 2 and closer in style to the more fragmented wave 3 disclosed on August 2. 

That third wave used individual destination addresses, P2WSH outputs, batching, and only the default derivation path, and Galaxy already noted at the time that it could not be assumed to share an operator with the first two waves.

The takeaway is not that a single attacker is expanding. The takeaway is that the Coldcard key space itself has become an open hunting ground and multiple groups appear to be racing across it in parallel.

RBF opt-in creates a narrow rescue window

The most operationally significant part of Thorn’s post was not the confirmed batch. It was the pending one. He flagged that additional matching transactions were still sitting unconfirmed in the mempool with Replace By Fee opt-in enabled, meaning the attacker had left the door open for a fee war.

For any Coldcard user whose address appears in the pending list, that changes the calculus. Instead of watching their coins move, they can broadcast a conflicting transaction spending the same UTXOs to a wallet they still control at a higher fee rate. 

Whichever transaction miners find more profitable is the one that confirms. Thorn framed it bluntly as a minutes-long window to engage in a fee race and secure funds. This is the first time in the Coldcard incident that a defensive lever has been available to victims in real time, and it only works while the transactions remain unconfirmed.

Nunchuk correction trims the wave 4 tally

Within a couple of hours of his initial post, Thorn issued two corrections that reshaped the wave 4 numbers, a level of iteration that speaks more to the messy reality of live on-chain forensics than to any weakness in the underlying pattern match.

The first correction removed six destination addresses that turned out to have been receiving and spending Bitcoin long before block 960,183 on July 30, the block where the Coldcard incident began. A freshly generated attacker wallet cannot carry years of prior history, so those six were dropped from the attacker set, subtracting 5.39 BTC from the circulating figure. That left 210 of the 216 destinations as clean, fresh addresses fit the profile.

The second and larger correction came courtesy of Bitcoin multisig service Nunchuk, which flagged that the pastebin lists Thorn had published, covering both confirmed and mempool sweeps, had erroneously scooped up 89 multisig addresses. Since there are zero multisigs in waves 1 through 3, those 89 addresses and the 20.58 BTC attached to them were pulled out of the wave 4 set.

After both discounts, the revised impact reads:

  • As circulated: 857 addresses, 486.11 BTC
  • Less multisig false positives: 89 addresses, 20.58 BTC
  • Surviving cover: 709 addresses, roughly 448.73 BTC

Thorn was explicit that he used the word “likely” throughout the thread because the wave 4 attribution rests on pattern matching against irregular activity bursts rather than a direct victim report, and he asked anyone drained in the last few hours to reach out for corroboration.

Firmware root cause remains unpatched for existing seeds

The root cause has not changed since day one. A code commit dated March 1, 2021, shipped in Coldcard firmware 4.0.0 later that month, silently rerouted seed generation through a software fallback rather than the intended STM32 hardware random number generator. 

The result was that Mk3 seeds carried roughly 40 bits of effective entropy rather than the 128 bits assumed by the BIP-39 standard, and Mk4, Q, and Mk5 seeds around 72 bits due to their secure elements. On commodity hardware, a 40-bit search space is not a barrier. It is a weekend.

Coinkite, the Canadian firm behind Coldcard, has since shipped emergency firmware updates: version 4.2.0 for the Mk3 and 5.6.0 for the Mk4 and Mk5 and 1.5.0Q for the Q, but the fixes only apply to newly generated seeds. 

Anything created on affected firmware is permanently compromised at the seed level, which is why every wave to date has drained from addresses derived from those legacy seeds no matter how careful the user was afterward. Coinkite has also destroyed remaining vulnerable inventory and halted shipments, and CEO Rodolfo Novak has publicly acknowledged the company was unaware of the bug until researchers surfaced it.

Wider losses and market backdrop

Wave 4 lands on top of the 1,367 BTC drained across the first three waves that Galaxy had documented by August 2, valued at roughly 88.6 million dollars at then prevailing prices. If the wave 4 figure holds after victim confirmations, the cumulative Coldcard drain will sit near 1,816 BTC across more than 5,200 addresses, worth around 115 million dollars at current spot levels. That is before accounting for smaller opportunistic copycats, which Thorn has already warned are showing up around the edges of the main waves.

The market has absorbed the news better than early panic suggested. Bitcoin traded near the low $63,000s heading into the wave 4 disclosure, a level it has held despite a roughly 3 percent slide on the initial news and a wave of ETF outflows that saw BlackRock’s IBIT lead $265 million in Bitcoin ETF redemptions on July 31. On-chain analysts have separately flagged that more than 77,000 BTC was rotated out of long dormant wallets during the migration rush, distorting several standard on-chain signals that would otherwise read as heavy distribution.

Second-order effects are showing up too. Chainalysis previously documented that the wave 1 attacker went after the largest wallets first, extracting more than 30 million dollars in the opening ten minutes, a pattern that suggests the vulnerable key set had been quietly enumerated well before it was ever exploited. 

An OP_RETURN message reportedly hit one of the attacker addresses offering a 10 percent fee for laundering and KYC bypass services, an unmistakable signal that the wider illicit economy is now circling the stolen stack.

The bigger question for Bitcoin self-custody

Wave 4 lands during an unusually candid stretch of introspection in the self-custody community. Binance founder Changpeng Zhao publicly warned users not to place blind trust in hardware wallets, and analysts have started openly asking whether the mantra of not your keys not your coins needs a second clause about firmware provenance and entropy verification. 

The Coldcard incident is now widely grouped alongside the 2023 Milk Sad PRNG bug and the 2026 Ill Bloom mobile wallet breach as the third major documented failure in this class, and all three share the same brutal characteristic. The failure happens at wallet creation, a moment the user has no way to independently audit, no matter how carefully they operate the device afterward.

For anyone still holding funds on a single-signature Coldcard seed created on firmware 4.0.1 or later without meaningful additional entropy from dice rolls or a strong BIP-39 passphrase, the standing guidance from both Coinkite and Galaxy Research is unambiguous. 

Generate a fresh seed on an unaffected device, verify the backup, send a test transaction, and only then move the balance. For anyone whose address appears in Thorn’s wave 4 pastebin with a pending sweep still in the mempool, the window is measured in minutes, and the tool is Replace By Fee.

Also Read: Michael Saylor Says BIP-110 Lacks Bitcoin Economic Consensus

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

CLARITY Act Absent From Senate Schedule as 72-Hour Deadline Looms
CLARITY Act Absent From Senate Schedule as 72-Hour Deadline Looms 
BitGo CEO Dares Anthropic’s Claude to Steal 100 BTC After Breach Disclosure
BitGo CEO Dares Anthropic’s Claude to Steal 100 BTC After Breach Disclosure
Crypto Week Ahead: CLARITY Act Deadline, Jobs Data, Circle & SpaceX Earnings
Crypto Week Ahead: CLARITY Act Deadline, Jobs Data, Circle & SpaceX Earnings
Coinbase Stock Prediction: Can COIN Defy August’s Losing Streak?
July Crypto Stock Breakdown Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
July Crypto Stock Breakdown: Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped

Find Us on Socials

You may also like

Coldcard Hack Tops $88.6M as Galaxy Finds Third Attack Wave

Coldcard Hack Tops $88.6M as Galaxy Finds Third Attack Wave

Michael Saylor Says BIP-110 Lacks Bitcoin Economic Consensus

Michael Saylor Says BIP-110 Lacks Bitcoin Economic Consensus

Binance Founder Warns Crypto Users After Coldcard Hack Tops $70M

Binance Founder Warns Crypto Users After Coldcard Hack Tops $70M 

Coldcard Hack Hits $75M After Alleged Second Attack Wave: Galaxy Research

Coldcard Hack Hits $75M After Alleged Second Attack Wave: Galaxy Research

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information