A fourth wave of the ongoing Coldcard attack has been identified, with approximately 448.7 Bitcoin moving across hundreds of suspicious transactions. The attack exploits a firmware vulnerability that generates wallets with insufficient entropy, leading to the theft of over $90 million in Bitcoin from thousands of wallets.
Alex Thorn, research head at Galaxy Research, revealed that approximately 448.7 BTC was moved across several hundred transactions, suggesting a fourth organized attack on wallets generated using compromised Coldcard firmware.
The recent attack has involved 709 potential victim addresses, with attackers sweeping 13.8 wallets per Bitcoin block. This activity is 45 times higher than any previously observed before this incident.
Instead of consolidating funds in a single wallet, the majority of transactions create a new destination address for each victim. Some stolen Bitcoin has been sent to second-hop addresses to hinder recovery attempts.
Thorn stated that additional suspicious transactions remain in Bitcoin’s mempool awaiting confirmation, though users with control over affected private keys might be able to broadcast conflicting transactions with a higher fee using Replace-by-Fee (RBF).
Blockchain investigators as stated that 1,196 Bitcoin addresses were completely drained of 1,082.65 BTC, worth about $70.2 million, in just 41 minutes on July 30th. The coordinated theft occurred between 01:10:20 UTC and 01:51:26 UTC across Bitcoin blocks 960,183–960,191.
The attack has been associated with a previously unknown vulnerability within firmware, resulting in Coldcard devices producing wallet recovery seeds with less entropy than required. Estimates of affected wallets now number in the thousands.
Coldcard manufacturer Coinkite has suspended shipments of any device affected by the firmware version. Affected users have been asked to generate a new recovery seed and move their Bitcoin to new wallets using an updated version of the software.
