Fourth Coldcard Wave Drains 389 BTC as 2021 Firmware Flaw Fuels Ongoing Theft
A fourth wave of Coldcard wallet thefts swept 388.93 BTC across 218 transactions in 2.5 hours, as a 2021 firmware entropy flaw leaves more addresses at risk.
Alex Thorn, head of research at Galaxy Research, warned on August 3 that a fourth coordinated wave of thefts targeting Coldcard hardware wallet users is underway – with 388.93 BTC swept across 218 transactions in roughly 2.5 hours, according to supplementary reporting from KuCoin News, citing BlockBeats.
That figure is separate from the cumulative losses Galaxy had already documented across three prior waves. As of August 2, the firm had tracked approximately 1,367 BTC – roughly $88.6 million – drained from 4,585 addresses, per Decrypt’s reporting via Yahoo Finance. The fourth wave adds a new layer to an attack campaign that shows no sign of stopping.
Fourth Wave: 218 Transactions, 462 Addresses, Blocks 960778–960792
The fourth wave activity was detected across blocks 960778 through 960792, spanning approximately 2.5 hours. The 218 transactions involved 462 victim addresses, with transaction frequency running roughly 45 times above normal, according to KuCoin News. The pattern is described as highly consistent with the Coldcard UTXO signature Galaxy researchers had already identified across the prior three attack clusters.
Some funds from the fourth wave have already reached second-hop addresses, while additional transfers remained in the mempool with replace-by-fee (RBF) enabled at the time of reporting – meaning confirmed loss totals from this wave may still be rising as pending transactions clear. KuCoin News recommends that affected users promptly move their funds out of Coldcard-generated addresses using a high transaction fee. Thorn’s post on X warned holders to move funds immediately.
Galaxy also flagged the emergence of smaller imitators now targeting remaining vulnerable Coldcard mnemonic phrases – a structural complication that extends the campaign’s threat surface beyond the three coordinated waves the firm had originally mapped. One case Thorn assisted with saw funds withdrawn before they could be frozen on the Duel platform, and those funds fall outside the three documented wave totals.
The Root Cause: A March 2021 Firmware Entropy Flaw
The underlying flaw, as Decrypt previously reported, traces to a March 2021 firmware build error on Coinkite devices that caused seed phrases to be generated with severely insufficient randomness, leaving private keys mathematically guessable. Thorn has warned that every single-sig Coldcard address created after that 2021 update will eventually be drained, saying it is only a matter of time.
The attack methodology appears deliberate and programmatic. Thorn has noted that the sweep pattern is consistent with large-scale scripted execution, and has suggested the campaign is probably orchestrated with a large language model. The technical details of the firmware entropy flaw and the attacker’s pre-profiling methodology underscore that this is not opportunistic theft – the attacker identified vulnerable addresses systematically before initiating sweeps.
One data point reinforces how precisely the victims were selected: drained funds had sat dormant for an average of 3.18 years before being swept, per Decrypt’s reporting. These were long-term self-custody holders, not recent wallet setups – which means the damage falls disproportionately on the cohort of Bitcoin holders who took the most care with their security posture.
On-Chain Response: 600 Attacker Addresses Flagged, Coins Still Parked
Galaxy has flagged approximately 600 suspected attacker addresses to federal investigators, compliance firms, and cross-industry cyber investigators, crediting victims who shared transaction data for enabling the on-chain pattern mapping. Despite the scale of the theft, the stolen coins from the three documented prior waves have not moved – they remain parked in attacker-controlled addresses.

That dormancy in the attacker’s holdings creates a narrow window for potential recovery through exchange freezes if the funds do eventually move to a known custodian. The coordination required to execute 218 transactions across 462 addresses in 2.5 hours, at 45 times the baseline transaction frequency, points to a highly organized operation.
Canadian fitness coach Jonathan Goodman offered the campaign’s sharpest human data point in a post on X, writing that 18.25 BTC – worth approximately 1.6 million Canadian dollars – was swept from his wallets in a seven-minute window on July 29, despite his keys having never touched the internet and sitting in a safety deposit box. Goodman wrote that he had done everything right and confirmed he is filing reports with police and the Ontario Securities Commission.
Structural Implications for Self-Custody Holders
The campaign has produced a visible reversal in self-custody behaviour: affected users are racing funds off hardware wallets and back onto centralized exchanges including Coinbase and Binance, or to freshly generated addresses – a direct inversion of the hardware wallet security argument. Security experts have urged caution when moving funds to new addresses.
The episode is structurally distinct from a software breach or exchange hack. The entropy flaw is baked into the key generation process itself, meaning that affected wallets carry compromised private keys regardless of how the device was stored or handled after setup. Air-gapped storage, safety deposit boxes, and offline signing provided no protection once the seed was generated with insufficient randomness in March 2021.
Thorn posted to X that the attack is ongoing and that funds should be moved off Coldcard-generated addresses immediately. With a fourth wave now confirmed and smaller imitators entering the campaign, the set of actors targeting remaining vulnerable addresses is expanding – not contracting. What comes next depends on whether the attacker’s parked holdings begin moving through exchanges in ways that trigger compliance freezes, and whether Galaxy’s address database enables investigators to intercept proceeds before they disperse further into second and third-hop wallets.
Follow CoinNews on X and Telegram for real-time updates on the Coldcard investigation and Bitcoin security developments.