Galaxy Research head Alex Thorn warned early Monday that a fourth coordinated attack wave is likely targeting Coldcard users.

The random number generator (RNG) exploit has been linked to 1,367.05 Bitcoin (BTC) from 4,585 addresses across three confirmed waves. A verified fourth wave would push totals higher.

Coldcard Exploit Deepens as Suspected Fourth Wave Sweeps Over 380 Bitcoin

Thorn identified 218 transactions between blocks 960,778 and 960,792, moving over 380 BTC from 462 suspected victim addresses to 210 fresh destinations. Sweeps ran at 13.8 per block, roughly 45 times the pre-incident rate of 0.3.

The transactions matched the pattern of vulnerable Coldcard addresses, with some funds already swept to second-hop wallets.

“These are LIKELY Coldcard victims — they match the shape of coldcard vulnerable utxos and the elevated transaction pattern gives me high confidence they are another wave of attacks,” Thorn said.

The executive added that similar transactions remain pending in the mempool with replace-by-fee (RBF) enabled. RBF lets the sender replace an unconfirmed Bitcoin transaction with a higher-fee version. In some cases, this allows a victim to outbid an attacker’s competing transaction before either is confirmed.

Per Onchain Lens, confirmed losses stand at $88.6 million. Earlier waves drained individual holders in minutes, including one Canadian victim who lost $1.6 million.

Follow us on X to get the latest news as it happens

Coldcard Destroys Remaining Vulnerable Inventory

Meanwhile, Coldcard said Sunday it halted shipments and destroyed all remaining devices carrying the flawed firmware. Satscard, Opendime, and Tapsigner are unaffected.

The patched firmware protects only newly generated seeds. Users must create a fresh seed and migrate funds. The company also told victims to keep affected devices as its legal team coordinates with law enforcement.

“We’ve also been in direct contact with the wider hardware wallet and self-custody community, including other builders, researchers, and people who’ve thought hard about this kind of failure. All have graciously offered whatever resources they could spare. We are still engaged in this outreach and are committing to work with the broader industry going forward,” the team said.

The incident has already drawn warnings from CZ about hardware wallet risk. Whether wave 4 gains confirmation, and whether pending fee races rescue funds, may decide the final toll.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights

The post Coldcard Bitcoin Exploit Enters Fourth Wave With 462 New Suspected Victims appeared first on BeInCrypto.

Source: beincrypto.com →