Coldcard Wallet Losses Hit $114M as Fourth Theft Wave Emerges
Key Facts
Amid escalating cybersecurity threats targeting digital assets, reports have revealed a sharp increase in thefts targeting Coldcard wallet users. According to reports, total losses may reach $114 million following the detection of a fourth wave of unauthorized fund sweeps. These attacks stem from a vulnerability in the seed generation mechanism of Coldcard Mk3 devices, which has allowed attackers to drain Bitcoin balances in successive waves.
Technical data indicates that the currently pending transactions utilize the Replace-By-Fee (RBF) feature, offering victims a brief window to recover their funds before transaction confirmation. Per market data, this feature allows users to attempt moving their funds to secure addresses by paying higher transaction fees than those set by the attacker, provided the transaction remains in the mempool and has not yet been confirmed on the blockchain.
Investors should monitor for further security updates from manufacturer Coinkite, noting that the upcoming economic calendar does not list any direct catalysts for crypto-cybersecurity in the immediate days ahead.
Latest Updates · 2
- Major·
Update: On-chain data confirmed a mass migration of retail Bitcoin holders on July 31, with 39,600 BTC moved—the highest volume for this cohort since the FTX collapse. Daily active addresses spiked to nearly one million as users sought to secure their assets, while exchange deposits for small transfers hit a post-February high of $459 million.
- Notable·
Update: Galaxy Research has confirmed the detection of the fourth wave of thefts, noting that small Bitcoin transfers (under 1 BTC) have spiked to levels not seen since the FTX crisis. This surge in activity highlights the significant impact on retail users resulting from the identified security vulnerability.