Galaxy Research’s Alex Thorn has flagged what he described as a probable fourth organized wave of thefts targeting Coldcard hardware wallet users, warning on X on August 3 that the sweep was still in motion inside the mempool at the time of his post. Unlike the previous three waves, which were dissected only after the fact, wave 4 was called out while affected users still had a technical route to save their coins.
The head of firmwide research at Galaxy Digital said the confirmed portion of the sweep had already moved 388.93 BTC across 218 transactions from 462 victim addresses to 216 freshly created destinations, all landing in blocks 960,778 through 960,792 over a rolling window of roughly two and a half hours.
Every one of those inputs sat on the wrong side of the March 2021 Coldcard firmware boundary, the same regression that has powered every wave since July 30.
Rate spike and topology point to another coordinated operator
For an analyst, the numbers behind wave 4 matter less than their shape. Thorn measured the sweep rate at 13.8 transfers per block against a pre-incident control window of 0.3 per block, an elevation of roughly 45 times baseline. That kind of clustering is not a run of bad luck. It is the fingerprint of an automated pipeline chewing through a pre-computed list of vulnerable keys against a live mempool.
The topology matters just as much. Every victim in the confirmed set was routed to its own fresh destination address in a strict one-to-one mapping, and only a single destination received two sweeps. There is no collector wallet funneling coins into a consolidation point, which sets wave 4 apart from wave 1 and wave 2 and closer in style to the more fragmented wave 3 disclosed on August 2.
That third wave used individual destination addresses, P2WSH outputs, batching, and only the default derivation path, and Galaxy already noted at the time that it could not be assumed to share an operator with the first two waves.
The takeaway is not that a single attacker is expanding. The takeaway is that the Coldcard key space itself has become an open hunting ground and multiple groups appear to be racing across it in parallel.
RBF opt-in creates a narrow rescue window
The most operationally significant part of Thorn’s post was not the confirmed batch. It was the pending one. He flagged that additional matching transactions were still sitting unconfirmed in the mempool with Replace By Fee opt-in enabled, meaning the attacker had left the door open for a fee war.
For any Coldcard user whose address appears in the pending list, that changes the calculus. Instead of watching their coins move, they can broadcast a conflicting transaction spending the same UTXOs to a wallet they still control at a higher fee rate.
Whichever transaction miners find more profitable is the one that confirms. Thorn framed it bluntly as a minutes-long window to engage in a fee race and secure funds. This is the first time in the Coldcard incident that a defensive lever has been available to victims in real time, and it only works while the transactions remain unconfirmed.
Nunchuk correction trims the wave 4 tally
Within a couple of hours of his initial post, Thorn issued two corrections that reshaped the wave 4 numbers, a level of iteration that speaks more to the messy reality of live on-chain forensics than to any weakness in the underlying pattern match.
The first correction removed six destination addresses that turned out to have been receiving and spending Bitcoin long before block 960,183 on July 30, the block where the Coldcard incident began. A freshly generated attacker wallet cannot carry years of prior history, so those six were dropped from the attacker set, subtracting 5.39 BTC from the circulating figure. That left 210 of the 216 destinations as clean, fresh addresses fit the profile.
The second and larger correction came courtesy of Bitcoin multisig service Nunchuk, which flagged that the pastebin lists Thorn had published, covering both confirmed and mempool sweeps, had erroneously scooped up 89 multisig addresses. Since there are zero multisigs in waves 1 through 3, those 89 addresses and the 20.58 BTC attached to them were pulled out of the wave 4 set.
After both discounts, the revised impact reads:
- As circulated: 857 addresses, 486.11 BTC
- Less multisig false positives: 89 addresses, 20.58 BTC
- Surviving cover: 709 addresses, roughly 448.73 BTC
Thorn was explicit that he used the word “likely” throughout the thread because the wave 4 attribution rests on pattern matching against irregular activity bursts rather than a direct victim report, and he asked anyone drained in the last few hours to reach out for corroboration.
Firmware root cause remains unpatched for existing seeds
The root cause has not changed since day one. A code commit dated March 1, 2021, shipped in Coldcard firmware 4.0.0 later that month, silently rerouted seed generation through a software fallback rather than the intended STM32 hardware random number generator.
The result was that Mk3 seeds carried roughly 40 bits of effective entropy rather than the 128 bits assumed by the BIP-39 standard, and Mk4, Q, and Mk5 seeds around 72 bits due to their secure elements. On commodity hardware, a 40-bit search space is not a barrier. It is a weekend.
Coinkite, the Canadian firm behind Coldcard, has since shipped emergency firmware updates: version 4.2.0 for the Mk3 and 5.6.0 for the Mk4 and Mk5 and 1.5.0Q for the Q, but the fixes only apply to newly generated seeds.
Anything created on affected firmware is permanently compromised at the seed level, which is why every wave to date has drained from addresses derived from those legacy seeds no matter how careful the user was afterward. Coinkite has also destroyed remaining vulnerable inventory and halted shipments, and CEO Rodolfo Novak has publicly acknowledged the company was unaware of the bug until researchers surfaced it.
Wider losses and market backdrop
Wave 4 lands on top of the 1,367 BTC drained across the first three waves that Galaxy had documented by August 2, valued at roughly 88.6 million dollars at then prevailing prices. If the wave 4 figure holds after victim confirmations, the cumulative Coldcard drain will sit near 1,816 BTC across more than 5,200 addresses, worth around 115 million dollars at current spot levels. That is before accounting for smaller opportunistic copycats, which Thorn has already warned are showing up around the edges of the main waves.
The market has absorbed the news better than early panic suggested. Bitcoin traded near the low $63,000s heading into the wave 4 disclosure, a level it has held despite a roughly 3 percent slide on the initial news and a wave of ETF outflows that saw BlackRock’s IBIT lead $265 million in Bitcoin ETF redemptions on July 31. On-chain analysts have separately flagged that more than 77,000 BTC was rotated out of long dormant wallets during the migration rush, distorting several standard on-chain signals that would otherwise read as heavy distribution.
Second-order effects are showing up too. Chainalysis previously documented that the wave 1 attacker went after the largest wallets first, extracting more than 30 million dollars in the opening ten minutes, a pattern that suggests the vulnerable key set had been quietly enumerated well before it was ever exploited.
An OP_RETURN message reportedly hit one of the attacker addresses offering a 10 percent fee for laundering and KYC bypass services, an unmistakable signal that the wider illicit economy is now circling the stolen stack.
The bigger question for Bitcoin self-custody
Wave 4 lands during an unusually candid stretch of introspection in the self-custody community. Binance founder Changpeng Zhao publicly warned users not to place blind trust in hardware wallets, and analysts have started openly asking whether the mantra of not your keys not your coins needs a second clause about firmware provenance and entropy verification.
The Coldcard incident is now widely grouped alongside the 2023 Milk Sad PRNG bug and the 2026 Ill Bloom mobile wallet breach as the third major documented failure in this class, and all three share the same brutal characteristic. The failure happens at wallet creation, a moment the user has no way to independently audit, no matter how carefully they operate the device afterward.
For anyone still holding funds on a single-signature Coldcard seed created on firmware 4.0.1 or later without meaningful additional entropy from dice rolls or a strong BIP-39 passphrase, the standing guidance from both Coinkite and Galaxy Research is unambiguous.
Generate a fresh seed on an unaffected device, verify the backup, send a test transaction, and only then move the balance. For anyone whose address appears in Thorn’s wave 4 pastebin with a pending sweep still in the mempool, the window is measured in minutes, and the tool is Replace By Fee.
Also Read: Michael Saylor Says BIP-110 Lacks Bitcoin Economic Consensus
