LockurBlock Digital News & Media Platform

collapse
Home / Daily News Analysis / Coldcard wallet losses may near $114 million as possible fourth sweep emerges

Coldcard wallet losses may near $114 million as possible fourth sweep emerges

Aug 08, 2026  Twila Rosenbaum 5 views
Coldcard wallet losses may near $114 million as possible fourth sweep emerges

Bitcoin cold-wallet losses may near $114 million as researchers track a possible fourth sweep targeting funds generated by Coldcard, the popular hardware wallet from Coinkite. According to analysts monitoring blockchain activity, the attacker has moved approximately 1,816 bitcoin — worth around $114 million at current prices — from more than 5,200 addresses since July 30. The latest wave appears to involve transactions that use bitcoin's replace-by-fee (RBF) feature, giving victims a narrow window to outbid the attacker and rescue their coins before they are swept.

How the sweep works

Coldcard is a widely respected hardware wallet designed for cold storage of bitcoin. It is known for its focus on security and has been a favorite among privacy-conscious users. However, the ongoing series of sweeps suggests that a subset of Coldcard-generated addresses are vulnerable. The attacks do not appear to stem from a breach of Coldcard's firmware or the physical devices themselves. Instead, researchers suspect the issue may be related to how certain seeds are generated or backed up, potentially exposing private keys to the wider internet.

The sweeps began in late July and have continued in waves. The first three waves moved bitcoin from thousands of addresses, and now a fourth wave is emerging. Unlike earlier waves, the latest transactions are using replace-by-fee, a feature that allows a sender to broadcast a new version of an unconfirmed transaction with a higher fee. This is a critical clue for victims: if they notice their coins being swept while the transaction is still in the mempool, they can race the attacker by broadcasting their own transaction with a higher fee to move their funds to a safe address first.

Researchers point out that the use of RBF is a change in tactic. In the earlier waves, the attacker likely relied on low-fee transactions during periods of low network congestion, which could still be replaced. Now, by signaling RBF, the attacker is making it easier for themselves to bump fees if needed, but also revealing that the transactions are replaceable. This creates an opportunity for victims who are monitoring the mempool to reclaim their funds, though the window is measured in minutes.

The scale of the losses

The total losses are staggering. As of the latest data, more than 5,200 addresses have been drained, with about 1,816 bitcoin moved. At the time of writing, that is roughly $114 million. The attacker has been careful to funnel the stolen funds into previously unused addresses, making them harder to trace than in earlier waves. In the first waves, the attacker reused addresses and moved funds in a more transparent manner, which allowed researchers to track the flow. The new approach suggests a higher level of sophistication.

The pattern also strongly indicates that the vulnerability affects single-key Coldcard seeds, not multisignature setups. Multisignature wallets require multiple keys to authorize a transaction, and they typically add a layer of protection that seems to be absent in the affected addresses. Single-key wallets, where a single private key is sufficient to spend funds, are more exposed if that key is compromised. This has led security experts to advise users who have single-key Coldcard wallets to consider migrating to multisignature arrangements or to at least audit their seed generation process.

What is the underlying vulnerability?

As of now, the exact root cause of the vulnerabilities remains unclear. Some speculate that the affected seeds may have been generated using an online tool or a compromised air-gapped environment. Others point to possible weaknesses in the BIP-39 mnemonic generation process, especially if users opted for a dice roll or used a non-standard source of entropy. Coldcard itself has not issued a public statement linking the sweeps to a specific flaw in its products, but the company has historically been quick to respond to security issues.

One theory is that the attacker may have gained access to a database of seeds that were generated using a third-party service that claimed to be compatible with Coldcard. Another theory involves the use of "watching-only" descriptors that could have leaked private key material via an online connection. Since Coldcard is a cold-storage device, it should never connect to the internet directly, but users might have exported the master public key or other metadata to software wallets for transaction coordination. If that metadata was generated from a weak seed, it could be enough to derive the private keys.

Implications for the bitcoin community

This incident serves as a stark reminder that even hardware wallets are not immune to compromise if the user's seed generation and backup practices are flawed. Coldcard is often considered one of the most secure hardware wallets on the market, and its users tend to be technically skilled. Yet the sheer number of affected addresses suggests that a common mistake has been repeated by thousands of people.

The use of replace-by-fee in the latest wave is also a double-edged sword. On one hand, it gives victims a chance to rescue their funds. On the other hand, it indicates that the attacker is not concerned about leaving traces on the mempool. They may be operating under the assumption that most victims are not monitoring the mempool or are not knowledgeable enough to take advantage of the RBF mechanism. This is likely true, as the average bitcoin holder may not check the mempool regularly.

For those who do spot their coins in the mempool, an RBF-enabled transaction can be replaced by broadcasting a new transaction with a higher fee that spends the same inputs. This is a standard feature and does not require special skills, but it does require quick action and an available wallet that has the private keys. Since the funds are being drained from addresses that are presumably controlled by the victims, they have the ability to move the coins themselves if they can beat the attacker's fee.

Security researchers are urging all Coldcard users to check their addresses for any suspicious outbound transactions. They also recommend that users avoid reusing addresses and ensure that their seed phrases are generated using hardware-based randomness. The fact that the attacker is sending funds to previously unused addresses makes it harder for blockchain analytics firms to identify the ultimate destination, which could complicate recovery efforts.

Lessons for hardware wallet users

This event highlights the importance of understanding the entire security model of a hardware wallet. The device itself is only as secure as the environment in which it is set up. If a user generates a seed phrase on a computer that is connected to the internet, even briefly, that seed may be compromised. Coldcard and other hardware wallets generally provide instructions to generate seeds directly on the device, but some users may have taken shortcuts.

Multisignature setups are looking increasingly attractive as a result of this incident. By requiring two or more keys from separate devices, multisignature wallets can prevent a single point of failure. The fact that no multisignature addresses appear to have been affected suggests that the security of multisignature schemes is holding up. For users with large sums, migrating to a multisignature arrangement could be a prudent move, even if it adds some inconvenience.

Meanwhile, the bitcoin community is watching the attacker's movements closely. The fourth sweep may not be the last. As more information emerges, researchers hope to pin down the exact cause and release tools to help users test whether their seed generation process is vulnerable. In the meantime, anyone with a Coldcard single-key wallet should treat any unexpected transaction as a potential attack and prioritize moving their funds to a newly generated address using a device that has never been connected to the internet.

The next few days could be critical for anyone who believes they might be affected. By monitoring the mempool for pending transactions from their known addresses, users may be able to use replace-by-fee to save their bitcoin. The attacker's use of this feature is a small crack in their methodology, and victims who are alert and act fast may still be able to slip through it.


Source:Coindesk News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy