mt logoMyToken
ETH Gas
Tiếng việt

Coldcard Faces Fourth Organized Attack Wave—388.9 BTC Siphoned in Coordinated Blitz

sưu tầmcollect
đăng lạishare
bitcoin14 main

Coldcard users are facing a fourth wave of organized theft, and the numbers are no longer rounding errors. Alex Thorn, Head of Research at Galaxy Research, flagged a fresh burst of malicious activity that siphoned approximately 388.9 BTC from 462 victim addresses in just 14 blocks—between 960,778 and 960,792. The attack generated 218 transactions funneling bitcoin into 216 previously unseen destinations. Transaction volume spiked to roughly 45 times the pre-incident baseline, leaving little doubt that this was a deliberate, structured operation.

The warning came via the original report , which also notes that some of the stolen funds have already been traced to second-hop addresses. Similar transactions remain pending in the mempool, indicating the sweep isn’t fully processed. Confirmed on-chain activity shows a signaled opt-in for Replace-by-Fee (RBF), a detail that could offer a narrow escape path for victims who act fast.

The Latest Attack Wave

What separates this wave from opportunistic theft is the speed and coordination. The 462 addresses were hit in a tight block window, with the outflow moving to destinations that hadn’t been used before. That pattern—fresh addresses, high-velocity consolidation, and volume far above normal—suggests pre-planned scripts rather than a manual actor. The theft occurred on a weekend, when many users may not have been monitoring transactions. Galaxy Research noted that some funds were already swept to second-hop wallets, complicating track-and-trace efforts and making recovery unlikely without immediate intervention.

The RBF flag offers a lifeline, but only for those who notice the attack while their transactions are still replaceable. Users with pending, unconfirmed outgoing transactions that haven’t been broadcast with a low fee could potentially accelerate a competing transaction to a safe address. It’s a slim window, and it requires technical awareness. For most victims, the funds are already gone.

Pattern of Organized Theft

This isn’t the first ride for Coldcard owners. According to Galaxy Research, earlier waves identified three separate attack campaigns targeting Coldcard-generated addresses. Cumulatively, those waves drained 1,367.05 BTC from 4,585 addresses—worth roughly $88.6 million at the time of the thefts. The earlier incidents pushed Coldcard to acknowledge a firmware vulnerability that allowed attackers to derive private keys from seeds created on affected devices.

The hardware manufacturer halted shipments and destroyed all remaining COLDCARD devices with the vulnerable firmware. Satscard, Opendime, and Tapsigner products were unaffected. Coldcard released a patched firmware that protects newly generated seeds, but the fix is not retroactive. Any seed created on the vulnerable firmware remains compromised. The firm’s guidance is blunt: create a new seed on patched firmware and move all funds off old seeds immediately. The fourth wave shows that many users have not yet done so, and attackers are exploiting that inertia systematically.

Coldcard’s Response and User Guidance

Coldcard’s decision to halt shipments and destroy inventory was a drastic but necessary step that other hardware vendors rarely take publicly. It signaled that the vulnerability was not a theoretical edge case. Yet the patch rollout exposes the friction inherent in self-custody. Users must generate a new seed phrase, a process that forces a complete change of wallet addresses and often requires updating connected software wallets, multisig setups, and backup procedures. That migration is not trivial, and the ongoing attack waves are punishing anyone who delayed.

For those still holding funds on a seed that originated on the vulnerable firmware, the advice from Galaxy Research is urgent: move funds off Coldcard devices now, use higher-than-usual fees to push transactions through, and exploit RBF if your wallet supports it. The address drain in the fourth wave indicates that attackers are actively monitoring the network for remaining balances.

Broader Implications for Self-Custody

The Coldcard episode is more than a hardware bug—it exposes the supply-chain and lifecycle risks baked into self-custody. Users trust firmware that ships from a manufacturer, and even open-source verification processes can be skipped. When a seed generation flaw goes unnoticed for months, the subsequent cleanup is messy and slow. The fact that four distinct attack waves could occur, each months apart, suggests that the attacker is patient and has a reliable method for matching seeds to addresses, likely from a dumped extract of the weak randomness period.

What’s still unclear is whether the attacker holds all of the compromised seed list or only a subset, and whether additional vulnerabilities exist in earlier firmware versions that Coldcard hasn’t disclosed. The sustained nature of the attacks indicates that the list may be large, and the 462 addresses in this wave may be only the latest batch. If the attacker continues sweeping systematically, total losses could climb further. For the broader hardware wallet market, the fallout is a reminder that firmware audits and transparent vulnerability reporting are not optional—they are the core of the product’s security promise.

Tuyên bố từ chối trách nhiệm: Bản quyền của bài viết này thuộc về tác giả gốc và không đại diện cho MyToken(www.mytokencap.com)Ý kiến ​​và vị trí; vui lòng liên hệ với chúng tôi nếu bạn có thắc mắc về nội dung
community_x_prefix
X(https://x.com/MyTokencap)
community_tg_prefixcommunity_tg_name
https://t.me/mytokenGroup
Đọc liên quan