A fourth wave of Bitcoin sweeps targeting addresses created by the Coldcard hardware wallet vulnerability began early Monday and continued for several hours. However, this latest wave differs from previous attacks because researchers say affected transactions can still be replaced before they are confirmed on the blockchain.
Galaxy Research head of firmwide research Alex Thorn identified the ongoing activity and noted that the attackers used Bitcoin’s replace-by-fee (RBF) feature. This mechanism allows an unconfirmed transaction to be replaced by another transaction with a higher fee. As a result, victims who notice their address appearing in the mempool — Bitcoin’s waiting area for pending transactions — may still have a short window to submit a higher-fee transaction and transfer their funds first.
The initial attack began on July 30, when attackers drained 1,083 BTC from 1,196 addresses within roughly 41 minutes. Two additional waves over the weekend increased the confirmed losses to 1,367 BTC spread across 4,585 addresses.
The vulnerability behind the exploit originated from a March 2021 Coldcard firmware version that mistakenly used a predictable software-based random number generator instead of the device’s hardware randomness source for seed creation. This allowed attackers who identified the affected seed range to recreate private keys offline.
Coldcard manufacturer Coinkite issued emergency firmware updates for impacted devices and advised users who created wallets with vulnerable firmware to transfer funds to new addresses generated from fresh seeds.
Thorn said he had not received direct reports from victims and that his analysis was based on transaction patterns and address similarities. He said he prioritized releasing the information quickly because some transactions were still unconfirmed and could potentially be intercepted.
If the latest activity is confirmed, the total amount drained across all four waves would reach approximately 1,816 BTC, worth nearly $114 million, affecting more than 5,200 addresses since July 30.
Thorn urged affected users to immediately review their balances, remove funds from vulnerable devices, and use higher transaction fees where possible to prevent attackers from confirming the transfers.
The latest activity was observed across blocks 960,778 through 960,792, involving 218 transactions that affected 462 victim addresses. The attack rate reached around 14 sweeps per block, compared with roughly 0.3 sweeps per block during a pre-incident comparison period — nearly 45 times the normal level.
Analysis showed that each stolen BTC transfer occurred after the vulnerable Coldcard firmware cutoff, while the receiving addresses were newly created with no previous transaction history. Unlike earlier waves that used shared collection addresses, these transactions appeared to use separate destination addresses for individual victims.
None of the first three attack waves involved multisignature wallets, supporting the view that the vulnerability primarily affected single-key seed generation. Researchers also identified six destination addresses with older transaction histories, suggesting they were not newly created attacker wallets.

More Stories
Strategy Trims Bitcoin Holdings by $105M While Boosting STRC Share Repurchases
Bitcoin and Ether Slide as Coldcard Wallet Exploit Extends Into Fifth Day
Bitcoin Futures Premium Crashes as Yields Sink Below U.S. Treasury Returns