Coldcard wallet losses may near $114 million as possible fourth sweep emerges

A security vulnerability in older Coldcard hardware wallets has led to a series of attacks resulting in potential losses of up to $114 million in Bitcoin. The flaw stems from a 2021 firmware issue that allowed attackers to predict and reproduce private keys.
Why it matters
This incident underscores the critical importance of firmware security and regular updates in the self-custody cryptocurrency ecosystem.
Alex Thorn, head of firmwide research at Galaxy Research, flagged the active wave and said the attackers opted into replace-by-fee, a Bitcoin feature that lets a pending transaction be overwritten by a later one paying a higher fee. Until a transaction confirms, a victim who finds their address in the mempool — the queue of unconfirmed transactions — can pay more and move the coins out first.
The attack started July 30 in a sweep that took 1,083 bitcoin from 1,196 addresses in 41 minutes. Two further waves over the weekend brought observed losses to 1,367 bitcoin across 4,585 addresses.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in