Share
Subscribe to the AlphaWire Newsletter
A fourth suspected sweep of Coldcard-generated Bitcoin addresses moved 388.93 BTC from 462 addresses in roughly two and a half hours, according to Galaxy Research head Alex Thorn.
The activity suggests the threat remained active after Coinkite’s July 30 disclosure because installing patched firmware doesn’t secure seeds generated under the flawed process.
Thorn identified 218 transactions between Bitcoin blocks 960,778 and 960,792, moving funds from 462 suspected victim addresses to 216 newly created wallets. The sweep rate reached 13.8 transactions per block, compared with a pre-incident average of 0.3, representing roughly a 45 fold increase. Nearly every affected address transferred its funds to a unique destination, and some of the Bitcoin has already been moved to second hop addresses.
🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW
THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS
pattern identified:
blocks…— Alex Thorn (@intangiblecoins) August 3, 2026
Galaxy’s classification remains provisional. Thorn described the activity as suspected because the finding comes from transaction patterns rather than a confirmed list of victims. The 45-fold activity spike and one-to-one routing pattern are consistent with an automated sweep, but on-chain data can’t determine whether the same operator controlled earlier waves or whether every flagged address belonged to a victim.
Some matching transactions were still waiting in Bitcoin’s mempool when Thorn raised the alert. The attacker’s transactions signaled Replace-by-Fee (RBF) support, potentially allowing an affected user who still controlled the keys to broadcast a conflicting transaction with a higher fee and redirect the same unspent outputs to a safe wallet.
The outcome depended on which transaction miners confirmed first, leaving users with a narrow rescue window rather than a guaranteed recovery route.
Coinkite traced the exposure to a March 2021 integration error that sent seed generation through a MicroPython software fallback instead of the intended hardware random-number generator. The company estimates affected Mk2 and Mk3 seeds had about 40 bits of effective entropy, while later Mk4, Mk5 and Q models reached about 72 bits rather than the expected 128.
Block’s Bitcoin security team reached the same root cause but said it hadn’t completed full empirical testing of exploitability. Its review found that newer devices retained only a 32-bit secure-element reseed under fixed fallback conditions, narrowing the candidate space without proving that every affected seed would be equally practical to brute-force.
Coinkite has released fixed firmware, halted shipments and destroyed its remaining devices loaded with affected software. Installing the update doesn’t strengthen an existing seed. The company advised affected users to generate a new seed on fixed firmware, verify it with a test transaction and move the remaining balance.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share