Fourth Suspected Coldcard Attack Wave Moves 389 BTC Across 462 Addresses: Galaxy Research

 

By Muhammad Hassan // August 3, 2026 @ 08:14 AM Make AlphaWire Logo preferred on Google News
Fourth Suspected Coldcard Attack Wave Moves 389 BTC Across 462 Addresses: Galaxy Research

Share

Points of Focus

  • Galaxy Research tracked 388.93 BTC moving from 462 suspected victim addresses in about 2.5 hours.
  • Sweep activity jumped to 45 times the pre-incident rate.
  • RBF offered a brief rescue window, but firmware updates can’t fix exposed seeds.

 

A fourth suspected sweep of Coldcard-generated Bitcoin addresses moved 388.93 BTC from 462 addresses in roughly two and a half hours, according to Galaxy Research head Alex Thorn

The activity suggests the threat remained active after Coinkite’s July 30 disclosure because installing patched firmware doesn’t secure seeds generated under the flawed process.

 

Coldcard wave four shows a new sweep pattern

Thorn identified 218 transactions between Bitcoin blocks 960,778 and 960,792, moving funds from 462 suspected victim addresses to 216 newly created wallets. The sweep rate reached 13.8 transactions per block, compared with a pre-incident average of 0.3, representing roughly a 45 fold increase. Nearly every affected address transferred its funds to a unique destination, and some of the Bitcoin has already been moved to second hop addresses. 

 

 

Galaxy’s classification remains provisional. Thorn described the activity as suspected because the finding comes from transaction patterns rather than a confirmed list of victims. The 45-fold activity spike and one-to-one routing pattern are consistent with an automated sweep, but on-chain data can’t determine whether the same operator controlled earlier waves or whether every flagged address belonged to a victim.

 

RBF offers a narrow rescue window

Some matching transactions were still waiting in Bitcoin’s mempool when Thorn raised the alert. The attacker’s transactions signaled Replace-by-Fee (RBF) support, potentially allowing an affected user who still controlled the keys to broadcast a conflicting transaction with a higher fee and redirect the same unspent outputs to a safe wallet.

 The outcome depended on which transaction miners confirmed first, leaving users with a narrow rescue window rather than a guaranteed recovery route.

 

Coldcard firmware patch can’t repair exposed seeds

Coinkite traced the exposure to a March 2021 integration error that sent seed generation through a MicroPython software fallback instead of the intended hardware random-number generator. The company estimates affected Mk2 and Mk3 seeds had about 40 bits of effective entropy, while later Mk4, Mk5 and Q models reached about 72 bits rather than the expected 128.

Block’s Bitcoin security team reached the same root cause but said it hadn’t completed full empirical testing of exploitability. Its review found that newer devices retained only a 32-bit secure-element reseed under fixed fallback conditions, narrowing the candidate space without proving that every affected seed would be equally practical to brute-force.

Coinkite has released fixed firmware, halted shipments and destroyed its remaining devices loaded with affected software. Installing the update doesn’t strengthen an existing seed. The company advised affected users to generate a new seed on fixed firmware, verify it with a test transaction and move the remaining balance.

Share

Default avatar

Muhammad Hassan

Muhammad Hassan is a tech writer with over 11 years of experience in the crypto space. He specializes in crafting data-driven strategic content that helps blockchain and fintech brands grow their organic reach. He has led editorial initiatives for global crypto media outlets, where his strategies and article series have reached millions of readers worldwide.

Table of content

Ad

Related Articles