Suspected Fourth COLDCARD Attack Wave Moves 388.9 BTC From 462 Addresses
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- A suspected fourth COLDCARD attack wave moved 388.93 BTC from 462 possible victims in just hours.
- Alex Thorn said more suspicious transactions were still waiting, suggesting the coordinated Bitcoin theft was continuing.
- COLDCARD warned affected users to create new seeds and move funds because older seeds remain unsafe.
A suspected fourth organized attack wave targeting Bitcoin addresses linked to vulnerable COLDCARD wallet seeds was still unfolding early on August 3, according to Galaxy Research Head Alex Thorn. In a post on X, Thorn said the activity had moved about 388.93 BTC through 218 transactions involving 462 possible victim addresses over roughly two and a half hours.
Thorn reported that the transactions appeared between Bitcoin blocks 960,778 and 960,792. He identified 216 destination addresses and said nearly all were newly created. The transaction rate was also around 45 times higher than the level recorded during a pre-incident control period.
🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW
THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS
pattern identified:
blocks…— Alex Thorn (@intangiblecoins) August 3, 2026
Possible COLDCARD Victims Face Ongoing Bitcoin Sweeps
The transaction pattern was mainly one-to-one. Each suspected victim address sent Bitcoin to a separate destination instead of one central collection wallet. Thorn said some of the funds had already moved to second-hop addresses. However, he described the link to COLDCARD victims as “likely,” rather than fully confirmed. His assessment was based on the transaction pattern and the finding that none of the inputs predated the affected COLDCARD firmware boundary.
Thorn later corrected part of his destination list by removing six addresses. Still, he said the remaining findings stood. He also warned that similar transactions were waiting in Bitcoin’s mempool. The mempool is where unconfirmed transactions remain before miners add them to a Bitcoin block.
Some pending transfers had replace-by-fee, or RBF, enabled. RBF allows a sender to replace an unconfirmed Bitcoin transaction with another transaction that pays a higher network fee. Thorn urged affected users to check their addresses immediately. In some cases, users may be able to protect their Bitcoin by creating a replacement transaction with a higher fee before the attacker’s transfer receives confirmation. However, such a fee race is highly time-sensitive and does not guarantee success.
The security crisis began on July 30, when researchers detected a coordinated sweep of Bitcoin addresses linked to weak wallet keys. Atlas21 initially reported that 594.5 BTC was removed from 500 single-signature addresses within about 15 minutes. Later analysis found that the opening attack may have affected 1,196 addresses and moved 1,082.65 BTC.
The attacks were linked to a problem in how some COLDCARD firmware versions generated seed phrases. A seed phrase controls the private keys needed to spend Bitcoin. Normally, it must contain enough random information to make it impossible to guess. However, affected COLDCARD seeds had less randomness than expected, which may have allowed attackers to calculate some private keys without gaining physical access to the devices.
COLDCARD Mk3 Security Advisory
If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk.
Mk4, Q and Mk5 are not affected based on our early analysis.
Read the advisory and migrate carefully:https://t.co/3vgPHOjMS7
— COLDCARD (@COLDCARDwallet) July 30, 2026
COLDCARD Responds After Bitcoin Theft Continues Through the Weekend
In a separate August 3 post on X, the company acknowledged the financial losses and personal hardship caused by the COLDCARD attack. The company said it had been working directly with customers since Friday to help move funds, review recovery options and answer urgent questions.
COLDCARD said it stopped shipping devices after confirming the security problem. It also destroyed its remaining devices that contained the vulnerable firmware. However, the company said its SATSCARD, OPENDIME and TAPSIGNER products are not affected. The company has released updated firmware to fix the problem. However, the update only protects new seed phrases created after installation. It cannot make an old seed phrase safe again.
Therefore, affected users should install the latest firmware and create a completely new seed phrase. They must then transfer their Bitcoin to a new wallet address connected to that seed. Users should complete the process carefully because any Bitcoin left in an affected wallet may remain at risk. COLDCARD also asked customers not to throw away affected devices. The devices may be useful during investigations or if stolen funds are later recovered. The company said its legal team will also work with law enforcement agencies in several countries.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







