Coldcard Wallets Hit by Fourth Attack Wave, 388 BTC Stolen
Galaxy Digital's Head of Research, Alex Thorn, reported a fourth wave of attacks targeting Coldcard hardware wallets. Approximately 388.93 Bitcoin was stolen in this latest wave, offering a narrow window for affected users to secure their funds.
A critical software vulnerability in Coldcard, a Bitcoin-only hardware wallet, has compromised the randomness of seed generation since March 2021 (firmware 4.0.1), leading to a significant security breach. Alex Thorn, Head of Research at Galaxy Digital, recently reported the detection of a fourth attack wave, with an additional 388.93 Bitcoin (BTC) being stolen. This incident has once again brought the importance of hardware wallet security and self-custody to the forefront of the cryptocurrency industry.
The vulnerability in Coldcard wallets, manufactured by Canadian firm Coinkite, stemmed from the seed generation process relying on a weak software pseudorandom number generator (PRNG) instead of the intended hardware random number generator (RNG). This flaw reduced the effective entropy from 128 bits to as low as 40 bits for Mk3 models and approximately 72 bits for Mk4, Mk5, and Q models, making private keys guessable. The initial major attack wave occurred on July 30-31, where approximately 594 BTC (worth about $38 million at the time) was drained from around 500 wallets within 25 minutes.
Detailed analysis by Galaxy Research revealed that the first three attack waves collectively resulted in the theft of 1,367.05 BTC (approximately $88.6 million) from 4,585 addresses. Alex Thorn's announcement on August 3 confirmed a fourth wave, where 388.93 BTC was moved through 218 transactions from 462 victim addresses over roughly two and a half hours. The transaction frequency during this latest attack wave was approximately 45 times higher than normal, strongly indicating an ongoing, coordinated effort.
Coinkite acknowledged the vulnerability and released emergency firmware updates for all affected models on July 31. However, the company clarified that installing the update does not automatically fix existing compromised seeds. Users must generate a *new* seed on patched firmware and transfer their funds to the new wallets. Some users even reported their devices becoming inoperable after attempting the update. Coinkite also speculated that artificial intelligence might have been used by attackers to discover the flaw.
This incident marks the largest Bitcoin theft of 2026 and has exerted some pressure on the markets. Bitcoin's price experienced a slight decline from $65,000 to $63,000. The unfolding security breach and the rush by Coldcard owners to move funds to secure addresses led to an unprecedented surge in small-value Bitcoin transfers, reaching levels not seen since the FTX collapse. This activity also distorted on-chain market signals, creating an impression of a broader selling wave.
Analysts and market experts have urged Coldcard users to monitor their pending transactions in the mempool and, if possible, utilize the Replace-By-Fee (RBF) feature with higher transaction fees to potentially override the attacker's transactions. Alex Thorn of Galaxy Digital emphasized that the attacks are still ongoing, with more small-scale copycat attackers emerging, and thus users who have not yet migrated their funds should act immediately. This event serves as a crucial reminder that even hardware wallets are not infallible, and users must remain vigilant in securing their digital assets.
Related Symbols
₿ Want to ride this crypto move?
Open an account in minutes. Compare brokers offering crypto and start investing today — zero commission options available.
Comments (0)
No comments yet. Be the first to comment!