Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Illustrated collage featuring diverse people surrounded by crypto symbols and a corporate boardroom backdrop.
    Quiet Racism in Crypto Gets “Obvious” During Circle’s Arc Mainnet Launch
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Bitcoin News

Coldcard Hack Enters Wave 4: 449 BTC Swept Live as Victims Race to Save Funds

Galaxy Research found Wave 4 moved 388.93 BTC across 218 transactions from 462 vulnerable Coldcard addresses, with on-chain patterns suggesting multiple coordinated attackers exploiting the same firmware flaw simultaneously.

Written By Dishita Malvania
Edited by Divya Mistry
Published 2026-08-03·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
Coldcard Hack Enters Wave 4 449 BTC Swept Live as Victims Race to Save Funds

Galaxy Research’s Alex Thorn has flagged what he described as a probable fourth organized wave of thefts targeting Coldcard hardware wallet users, warning on X on August 3 that the sweep was still in motion inside the mempool at the time of his post. Unlike the previous three waves, which were dissected only after the fact, wave 4 was called out while affected users still had a technical route to save their coins.

The head of firmwide research at Galaxy Digital said the confirmed portion of the sweep had already moved 388.93 BTC across 218 transactions from 462 victim addresses to 216 freshly created destinations, all landing in blocks 960,778 through 960,792 over a rolling window of roughly two and a half hours. 

AI Summary
Show
A firmware flaw in Coldcard hardware wallets has led to a series of thefts, with the root cause remaining unpatched for existing seeds, allowing attackers to exploit vulnerable key sets.
The wave 4 thefts demonstrate a coordinated effort, with a sweep rate 45 times higher than the baseline, and a topology that suggests multiple groups are racing to exploit the Coldcard key space.
The root cause of the issue dates back to a March 2021 code commit, which silently rerouted seed generation, resulting in reduced entropy and permanently compromised seeds, highlighting a need for improved security measures.

🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW

THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS

pattern identified:
blocks…

— Alex Thorn (@intangiblecoins) August 3, 2026

Every one of those inputs sat on the wrong side of the March 2021 Coldcard firmware boundary, the same regression that has powered every wave since July 30.

Rate spike and topology point to another coordinated operator

For an analyst, the numbers behind wave 4 matter less than their shape. Thorn measured the sweep rate at 13.8 transfers per block against a pre-incident control window of 0.3 per block, an elevation of roughly 45 times baseline. That kind of clustering is not a run of bad luck. It is the fingerprint of an automated pipeline chewing through a pre-computed list of vulnerable keys against a live mempool.

The topology matters just as much. Every victim in the confirmed set was routed to its own fresh destination address in a strict one-to-one mapping, and only a single destination received two sweeps. There is no collector wallet funneling coins into a consolidation point, which sets wave 4 apart from wave 1 and wave 2 and closer in style to the more fragmented wave 3 disclosed on August 2. 

That third wave used individual destination addresses, P2WSH outputs, batching, and only the default derivation path, and Galaxy already noted at the time that it could not be assumed to share an operator with the first two waves.

The takeaway is not that a single attacker is expanding. The takeaway is that the Coldcard key space itself has become an open hunting ground and multiple groups appear to be racing across it in parallel.

RBF opt-in creates a narrow rescue window

The most operationally significant part of Thorn’s post was not the confirmed batch. It was the pending one. He flagged that additional matching transactions were still sitting unconfirmed in the mempool with Replace By Fee opt-in enabled, meaning the attacker had left the door open for a fee war.

For any Coldcard user whose address appears in the pending list, that changes the calculus. Instead of watching their coins move, they can broadcast a conflicting transaction spending the same UTXOs to a wallet they still control at a higher fee rate. 

Whichever transaction miners find more profitable is the one that confirms. Thorn framed it bluntly as a minutes-long window to engage in a fee race and secure funds. This is the first time in the Coldcard incident that a defensive lever has been available to victims in real time, and it only works while the transactions remain unconfirmed.

Nunchuk correction trims the wave 4 tally

Within a couple of hours of his initial post, Thorn issued two corrections that reshaped the wave 4 numbers, a level of iteration that speaks more to the messy reality of live on-chain forensics than to any weakness in the underlying pattern match.

The first correction removed six destination addresses that turned out to have been receiving and spending Bitcoin long before block 960,183 on July 30, the block where the Coldcard incident began. A freshly generated attacker wallet cannot carry years of prior history, so those six were dropped from the attacker set, subtracting 5.39 BTC from the circulating figure. That left 210 of the 216 destinations as clean, fresh addresses fit the profile.

The second and larger correction came courtesy of Bitcoin multisig service Nunchuk, which flagged that the pastebin lists Thorn had published, covering both confirmed and mempool sweeps, had erroneously scooped up 89 multisig addresses. Since there are zero multisigs in waves 1 through 3, those 89 addresses and the 20.58 BTC attached to them were pulled out of the wave 4 set.

After both discounts, the revised impact reads:

  • As circulated: 857 addresses, 486.11 BTC
  • Less multisig false positives: 89 addresses, 20.58 BTC
  • Surviving cover: 709 addresses, roughly 448.73 BTC

Thorn was explicit that he used the word “likely” throughout the thread because the wave 4 attribution rests on pattern matching against irregular activity bursts rather than a direct victim report, and he asked anyone drained in the last few hours to reach out for corroboration.

Firmware root cause remains unpatched for existing seeds

The root cause has not changed since day one. A code commit dated March 1, 2021, shipped in Coldcard firmware 4.0.0 later that month, silently rerouted seed generation through a software fallback rather than the intended STM32 hardware random number generator. 

The result was that Mk3 seeds carried roughly 40 bits of effective entropy rather than the 128 bits assumed by the BIP-39 standard, and Mk4, Q, and Mk5 seeds around 72 bits due to their secure elements. On commodity hardware, a 40-bit search space is not a barrier. It is a weekend.

Coinkite, the Canadian firm behind Coldcard, has since shipped emergency firmware updates: version 4.2.0 for the Mk3 and 5.6.0 for the Mk4 and Mk5 and 1.5.0Q for the Q, but the fixes only apply to newly generated seeds. 

Anything created on affected firmware is permanently compromised at the seed level, which is why every wave to date has drained from addresses derived from those legacy seeds no matter how careful the user was afterward. Coinkite has also destroyed remaining vulnerable inventory and halted shipments, and CEO Rodolfo Novak has publicly acknowledged the company was unaware of the bug until researchers surfaced it.

Wider losses and market backdrop

Wave 4 lands on top of the 1,367 BTC drained across the first three waves that Galaxy had documented by August 2, valued at roughly 88.6 million dollars at then prevailing prices. If the wave 4 figure holds after victim confirmations, the cumulative Coldcard drain will sit near 1,816 BTC across more than 5,200 addresses, worth around 115 million dollars at current spot levels. That is before accounting for smaller opportunistic copycats, which Thorn has already warned are showing up around the edges of the main waves.

The market has absorbed the news better than early panic suggested. Bitcoin traded near the low $63,000s heading into the wave 4 disclosure, a level it has held despite a roughly 3% slide on the initial news and a wave of ETF outflows that saw BlackRock’s IBIT lead $265 million in Bitcoin ETF redemptions on July 31. On-chain analysts have separately flagged that more than 77,000 BTC was rotated out of long dormant wallets during the migration rush, distorting several standard on-chain signals that would otherwise read as heavy distribution.

Second-order effects are showing up too. Chainalysis previously documented that the wave 1 attacker went after the largest wallets first, extracting more than 30 million dollars in the opening ten minutes, a pattern that suggests the vulnerable key set had been quietly enumerated well before it was ever exploited. 

An OP_RETURN message reportedly hit one of the attacker addresses offering a 10% fee for laundering and KYC bypass services, an unmistakable signal that the wider illicit economy is now circling the stolen stack.

The bigger question for Bitcoin self-custody

Wave 4 lands during an unusually candid stretch of introspection in the self-custody community. Binance founder Changpeng Zhao publicly warned users not to place blind trust in hardware wallets, and analysts have started openly asking whether the mantra of not your keys not your coins needs a second clause about firmware provenance and entropy verification. 

The Coldcard incident is now widely grouped alongside the 2023 Milk Sad PRNG bug and the 2026 Ill Bloom mobile wallet breach as the third major documented failure in this class, and all three share the same brutal characteristic. The failure happens at wallet creation, a moment the user has no way to independently audit, no matter how carefully they operate the device afterward.

For anyone still holding funds on a single-signature Coldcard seed created on firmware 4.0.1 or later without meaningful additional entropy from dice rolls or a strong BIP-39 passphrase, the standing guidance from both Coinkite and Galaxy Research is unambiguous. 

Generate a fresh seed on an unaffected device, verify the backup, send a test transaction, and only then move the balance. For anyone whose address appears in Thorn’s wave 4 pastebin with a pending sweep still in the mempool, the window is measured in minutes, and the tool is Replace By Fee.

Also Read: Michael Saylor Says BIP-110 Lacks Bitcoin Economic Consensus

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

The Nostra logo in white and red centered over a dark red geometric pattern.
Nostra Halts Starknet Money Market After $3.5M NSTR Oracle Exploit
Ric Edelman, Bitcoin advocate in traditional finance
Ric Edelman Says Bitcoin Price Could Reach $500,000 by 2030
Neutrl Opens NUSD, sNUSD Redemptions as On-Chain Rate Reads 0.51
Neutrl Opens NUSD, sNUSD Redemptions as On-Chain Rate Reads 0.51
Smartphone displaying Solana price metrics in front of a backlit Solana logo display.
Solana Rises Above $100 as Traders Watch $105 Breakout Level
Hand holding a smartphone displaying the DUCAT logo in front of a Tron wall sign.
Ducat Expands to TRON with USDT and wUNIT for Settlements

Find Us on Socials

You may also like

Orange MicroStrategy logo with a Bitcoin symbol next to a Wall Street sign.

Bitcoin’s Liquidity Attraction: Michael Saylor’s Strategy (MSTR) Outpasses Berkshire Hathaway in Volume

A judge's gavel next to the Ostium logo inside a New York federal courtroom.

Ostium $15M Loan Dispute Reaches NY Federal Court Today After July $23.75M Oracle Exploit

A physical Bitcoin coin standing upright on a wet street with a illuminated "ETF" sign in the background.

Spot Bitcoin ETFs See $746M Outflow During CLARITY Act and FOMC Pressure

Hooded hacker targeting Revolut on laptop surrounded by monitoring displays.

Revolut Hackers Cut Ransom to $3M, Set 24-Hour Deadline to Sell 680 Customer Files: FT

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information