Loading prices...
All news
Coldcard wallet with a firmware bug

Coldcard hack: a fourth wave pushes losses toward $114 million

12:30 · 03.08.2026
1

The Coldcard wallet exploit isn't over — it keeps growing in waves. On the morning of August 3, Galaxy Research analyst Alex Thorn flagged a fourth wave of theft, and combined losses across all waves are now approaching $114 million, according to CoinDesk.

The attack's timeline: the first wave began on July 30 and took just 41 minutes, draining roughly 1,083 BTC. The second and third waves hit over the weekend, adding roughly 1,367 BTC to the running total. The fourth wave started early Monday morning — by Thorn's estimate, it hit around 462 victim addresses across blocks 960,778-960,792, with the rate of wallet "sweeps" jumping to roughly 14 per block versus 0.3 in the pre-incident baseline.

Every single-sig Coldcard address created after the March 2021 firmware flaw will eventually be drained.

Alex Thorn, Alex Thorn, Galaxy Research, post on X, August 3, 2026

The root cause traces back to a firmware commit from March 2021: seed generation for new wallets was quietly switched from the hardware random-number generator to a predictable software one, making keys partially reconstructable from data on the device itself. The issue only affects single-sig wallets — multisig setups aren't exposed. Coinkite, Coldcard's manufacturer, has already released emergency firmware and is advising owners to move funds onto freshly generated seed phrases.

We previously covered how the Coldcard attack grew to $89 million, and the situation hasn't slowed down since — it's just gone through another round. Some victims have a narrow window in the moment: the attacker is using Bitcoin's replace-by-fee feature, meaning an owner actively watching the mempool may have a few minutes to outbid the thief's fee and reclaim their own funds.

Thorn is describing the fourth wave as likely rather than fully confirmed, and the final tally is still being updated through the day. But the broader pattern is already clear: any Coldcard address generated over the past five years on the vulnerable firmware stays at risk until its funds are moved to a new key.

None of this should be read as personalized investment advice.

Published: 12:30 · 03.08.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!