A fourth wave of Bitcoin theft attempts connected to the Coldcard wallet vulnerability began early Monday and continued for several hours. However, researchers noted that this latest batch of transactions differs from earlier attacks because the transfers remain unconfirmed and may still be replaced before they are finalized.
Galaxy Research’s head of firmwide research, Alex Thorn, identified the active sweep and said the attackers used Bitcoin’s replace-by-fee (RBF) functionality. The feature allows a pending transaction to be replaced by another transaction with a higher fee. As a result, users who notice their wallet address appearing in the mempool — the queue of unconfirmed Bitcoin transactions — may have a brief opportunity to submit a higher-fee transaction and move their funds first.
The original attack started on July 30, with attackers draining 1,083 BTC from 1,196 wallet addresses within roughly 41 minutes. Two additional waves over the weekend pushed the confirmed losses to 1,367 BTC affecting 4,585 addresses.
The exploit was made possible by a flaw introduced in a March 2021 Coldcard firmware version. The issue caused wallet seed generation to rely on a predictable software randomizer instead of the device’s hardware random number generator, allowing attackers to reproduce private keys offline if they could determine the affected seed range.
Coldcard manufacturer Coinkite released emergency firmware updates for vulnerable devices and instructed users who created wallet seeds on affected firmware versions to move their funds to newly generated wallets using fresh seeds.
Thorn said he had not received direct confirmation from individual victims and that his analysis was based on blockchain patterns and transaction similarities. He said he released the findings quickly because some transfers were still pending, giving users a possible chance to protect their funds.
If the latest sweep is confirmed, total losses across all four attack waves would rise to approximately 1,816 BTC, worth close to $114 million, with more than 5,200 addresses affected since July 30.
Thorn advised users with potentially vulnerable wallets to immediately review their balances, transfer assets away from affected devices, and increase transaction fees when attempting to move funds ahead of the attacker’s pending transactions.
The activity was tracked across blocks 960,778 through 960,792, where 218 transactions targeted 462 victim addresses. The attackers carried out roughly 14 sweeps per block, compared with about 0.3 sweeps per block during the pre-incident comparison period, representing nearly a 45-times increase in activity.
Researchers found that the stolen BTC came from wallets created after the affected Coldcard firmware cutoff, while the receiving addresses were newly generated and had no previous transaction history. Unlike the first two attack waves, which relied on shared collection addresses and were easier to trace, the latest wave appeared to use separate destination addresses for each victim.
The first three attack waves did not involve multisignature wallets, suggesting that the vulnerability primarily impacted single-signature wallet seeds. Investigators also discovered six receiving addresses with older activity, indicating that not every destination address was newly created by the attacker.





