Hutchinson Kansas Newspaper

collapse
Home / Daily News Analysis / Coldcard wallet losses may near $114 million as possible fourth sweep emerges

Coldcard wallet losses may near $114 million as possible fourth sweep emerges

Aug 08, 2026  Twila Rosenbaum 6 views
Coldcard wallet losses may near $114 million as possible fourth sweep emerges

Bitcoin cold-wallet users may be facing a growing threat as security researchers track what appears to be a fourth wave of unauthorized sweeps from addresses generated by Coldcard hardware wallets. The new wave could push total estimated losses to nearly $114 million, making it one of the more significant hardware-wallet incidents in recent memory.

The Numbers Behind the Latest Sweep

Researchers monitoring bitcoin blockchain activity say the attacker has moved approximately 1,816 bitcoin, worth roughly $114 million at current prices, from more than 5,200 addresses since July 30. That staggering figure suggests the operation is not a random hit-and-run but a carefully orchestrated campaign targeting a specific weakness in address generation.

Bitcoin's on-chain data reveals the pattern: funds are being drained from addresses that appear to have been created by Coldcard hardware wallets. The attacker then sends the stolen coins to previously unused destination addresses, making the funds harder to trace than in earlier waves. This is a departure from previous sweeps, where stolen coins often moved to exchanges or well-known mixing services.

The latest transactions also carry a critical difference: they signal the use of bitcoin's replace-by-fee (RBF) feature. In a standard transaction, once a user broadcasts a transfer, they cannot easily change the fee. RBF allows the sender to replace an unconfirmed transaction with a new version that pays a higher fee per byte. This is a legitimate tool designed to help users escape stuck transactions during periods of network congestion. But in this case, the attacker appears to be using RBF to ensure their sweeps confirm quickly, even as network fees fluctuate.

What Replace-by-Fee Means for Victims

The use of RBF creates a narrow but important window for potential victims. When a pending transaction appears in the public mempool, anyone can see its inputs, outputs, and fee rate. Because the attacker's transaction is replaceable, the owner of the coins may be able to broadcast a competing transaction that spends the same inputs with a higher fee. If the victim's version confirms first, the attacker's sweep fails and the funds remain under the victim's control.

Security researchers emphasize that this is a race against time. A victim who spots their address in the mempool has only minutes to react. They need to create a transaction from their Coldcard wallet that spends the same coins, set a higher fee, and broadcast it to the network. This is not a simple process for non-technical users, especially those who have stored their hardware wallets away for long periods and may not have the device or software handy.

The fact that the attacker is using RBF suggests a sophisticated operator who understands bitcoin transaction mechanics deeply. It also indicates that the attacker is confident in their ability to sweep funds quickly, possibly by running custom node software that monitors mempools and automatically outbids competing transactions.

How the Pattern Was Detected

Independent researchers and blockchain analysts first noticed the initial wave of sweeps in late July 2024. The first wave drained a relatively small number of addresses, but the scale grew rapidly with each subsequent wave. By the time the third sweep was identified, losses had already climbed into the tens of millions of dollars. The fourth wave, now underway, has pushed the cumulative total toward $114 million.

Blockchain sleuths pieced together the pattern by looking at the structure of the addresses and the history of the funds held within them. The affected addresses showed characteristics consistent with Coldcard-generated single-key wallets, where a single BIP39 seed phrase derives all addresses. In contrast, multisignature setups have multiple keys and typically require signatures from several devices or seeds, making them far more resistant to this type of attack.

What remains unclear is the exact root cause. Some security experts suspect a flaw in the random number generator used by certain Coldcard devices, particularly older models. Others hypothesize that the seed phrases may have been compromised through a supply-chain attack, physical tampering, or side-channel leakage. No official explanation has been confirmed, and the investigation is still ongoing.

Single-Key vs. Multisignature: A Critical Distinction

One of the most important takeaways from the incident is the apparent distinction between single-key and multisignature Coldcard configurations. The affected addresses appear to be single-key derivations from Coldcard seeds. Multisignature wallets, which require multiple seeds and signatures to authorize a transaction, have not been hit in any of the four waves, according to researchers.

This distinction is a strong clue for users. Anyone using a single-signature Coldcard wallet should treat their funds as potentially at risk, especially if they generated their seed with an older device. Those using multisig setups may still want to move their coins out of caution, but the evidence suggests they are not the primary target.

Coldcard is a popular hardware wallet among bitcoin users who value security and open-source transparency. The device is designed to store private keys offline, making it immune to online attacks that often affect software wallets and exchange accounts. However, no hardware wallet is completely infallible, and this incident shows that even physical isolation cannot protect against certain kinds of weaknesses.

What Coldcard Users Should Do

In the wake of the fourth sweep, security researchers are advising all Coldcard users to take immediate action, even if they are not sure whether their addresses are affected. First, users should check whether their addresses appear in the list of compromised addresses shared by researchers. This information is publicly available and can be cross-referenced using a blockchain explorer.

Second, users should consider moving their funds to a newly generated address with a fresh seed. This is the safest option, as it completely separates the user's funds from any compromised key material. Those who generated their seed on an older Coldcard device should be especially cautious, as older firmware versions may contain vulnerabilities that have since been patched.

Third, users who notice a pending transaction from their wallet should not panic. Instead, they should immediately attempt to broadcast a higher-fee transaction to replace the attacker's sweeping transaction. Tools like Electrum and other advanced bitcoin wallets can create such transactions, though the process requires some technical knowledge. In some cases, a hardware wallet device itself may offer a way to bump the fee, but time is extremely limited.

Fourth, Coldcard users should upgrade their firmware to the latest version. The manufacturer has released security fixes over the years, and staying current is one of the simplest ways to protect against known vulnerabilities. Future firmware updates may also address any underlying issue related to this sweep campaign.

The Bigger Picture for Bitcoin Storage

This incident serves as a reminder that bitcoin self-custody comes with significant responsibility. Hardware wallets are often considered the gold standard for secure storage, but they are not immune to attacks. The Coldcard sweeps underscore the importance of understanding the exact configuration of one's wallet, including whether it is single-key or multisig, what firmware version it is running, and how the seed phrase was originally generated.

The attack also highlights the value of active monitoring. Bitcoin's transparent blockchain allows users to check their addresses at any time, but most people only look when they are ready to transact. Setting up alerts for any outgoing transaction from a cold-storage address could provide a crucial early warning, potentially giving users enough time to outbid an attacker's RBF transaction.

For those who are less technical, the safest approach may be to use a multisignature setup with hardware wallets from different manufacturers. This reduces the risk that a single flaw in one device or one seed-generation process can drain an entire wallet. The added complexity is significant, but so is the protection it provides.

As the investigation into the fourth sweep continues, more details may emerge about the exact mechanism of the attack. Until then, bitcoin holders with Coldcard wallets would be wise to err on the side of caution. Moving funds to a fresh address, enabling additional security layers, and staying informed about updates are all practical steps that can mitigate risk.

The bitcoin community has seen many types of theft over the years: exchange hacks, phishing campaigns, clipboard attacks, and malware. But a large-scale sweep of hardware-wallet addresses is relatively rare, and the near-$114 million toll makes this one of the biggest incidents in the sector. The final number could grow if the fourth wave continues to expand, or if additional waves emerge after this one concludes.

In the meantime, the race to secure vulnerable funds is underway. Every unconfirmed transaction in the mempool is a battle between the attacker and the potential victim. For those who act quickly, there is still a chance to save their bitcoin. For those who do not, the money may be gone forever.


Source:Coindesk News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy