Live Markets:
BTC Loading...
ETH Loading...
SOL Loading...
XRP Loading...
ADA Loading...
LTC Loading...
Cryptorah
Breaking
ZeroStack Flags Going-Concern Doubt After 0G Holdings Lose 91% of Their Cost Basis White House Teleprompter Operator Exits After $100K+ Prediction Market Scandal Trump Media Dumps $165M in Bitcoin as Coldcard Losses Hit $88M and FTX Pushes $900M to Creditors Trump Cancels Iran Strikes, Jobs Data Looms: Can Crypto Break Out This Week? Telegram now faces legal fire on three fronts at once, as Australia sues over terror content Stablecoins Offer No Systematic Edge Over Traditional Remittances, Bank of Italy Study Finds South Korea Weighs Interim Stablecoin Rules to Bridge the Gap Before Its Crypto Law Lands South Korea Moves Toward Unified Crypto Framework as Tax Repeal Debate Intensifies Senate Shelves Crypto Clarity Act as Russian Sanctions and Limited Floor Time Squeeze Industry's Regulatory Hopes Saylor's Warning: Bitcoin's Constitution Is Under Threat From Inside, Not Outside Russia Expands Cryptocurrency Mining Ban to Capital Region Through 2032 Pump.fun Layoffs Two Months Before Multi-Million Dollar Token Vesting Spark Controversy Onyx Security Lands $113M Series B to Police Autonomous AI Agents Inside the Enterprise New York Launches Legal Battle Against Kalshi, Alleging Illegal Gambling Operation Korean Police Crack Down on $8.6M XRP Staking Scam as Token Holds Ground Iran-Oman Talks Show Progress on Strait of Hormuz as Bitcoin Rallies Above $65K Hungary Scraps Crypto Validator Rule as CoinCash Secures First MiCA License Grayscale CEO Files to Sell Entire Pre-Conversion XRP Trust Stake as Fund Shrinks 51% Four Augusts in the Red: Can XRP Finally Break Its Bearish Summer Streak? Fed's Hawkish Hold Rattles Crypto: Bitcoin Defends $64K as Liquidations Top $300M EthSystems Launches Privacy Layer to Bridge Traditional Finance and Public Blockchains Crypto Industry Doubles Down on Michigan House Race with $2M Campaign Blitz Crypto Exchanges Go TradFi: Tokenized Stocks and Commodities Hit $6.6 Billion Crypto Braces for a Four-Catalyst Week: Iran Truce, CLARITY Act Vote, Fed Decision, PCE Data Critical Vulnerability in Coldcard Hardware Wallets: 594 BTC Stolen After Years-Long Entropy Flaw Coldcard's Weak-Seed Bug Claims a Fourth Wave — Nearly 449 BTC Moved in Hours Coldcard's Five-Year Randomness Bug: Why Auditors Missed a Silent Swap in the Wallet's Core Security Function Coldcard Firmware Attack Drains $70M in Bitcoin as Fear Index Hits All-Time High Coinbase Canada Pushes for Regulatory Clarity as It Eyes Derivatives and Tokenized Asset Expansion CFTC Warns Prediction Market Platforms Against Generic Event Contract Filings BlackRock and 140+ Institutions Launch Ethereum-Based Stablecoin as ETF Inflows Hit $11.2 Billion BitMart Shuts Down After 9 Years, BMX Token Crashes 58% Bitget to wind down Japan operations, force-close open positions by year-end Bitcoin Tests Critical $68,500 Resistance Wall as Fed Decision Looms Bitcoin Steadies Under $64K Post-FOMC as Pi Network Rallies and Talus (US) Storms the Top 100 Bitcoin Stalls at $63K While BEAT and MemeCore Post Double-Digit Weekend Gains Bitcoin Faces Four Converging Headwinds as Price Tests $62K Support Bitcoin Drops Below $64K as Korean Markets Crater and U.S. Crypto Bill Stalls Bitcoin and Gold Are Both Down Big — the "Quiet Accumulation" Story Behind Both Isn't as Clean as It Sounds Binance Wallet's $50,000 NES Perpetuals Competition: How Privacy-Focused AI Traders Can Compete Binance Adds Gold and Silver Options to Its Abu Dhabi-Regulated Exchange Bhutan Appoints 3iQ as First Institutional Manager for Bitcoin Treasury in Historic Sovereign Crypto Mandate Antora Energy Secures $550M to Scale Thermal Battery Manufacturing for AI Infrastructure and Industrial Heat Analyst Says Bitcoin's Cup-and-Handle Just Broke Out — With a $220K Minimum Target Aave Governance Weighs Pruning Six Blockchains and 50 Idle Markets in Risk-Framework Cleanup $3.6B EverSource Wealth Advisors Discloses XRP and Bitcoin ETF Holdings in Latest SEC Filing $10.4 Billion in Crypto Options Expire Today — Here's What the Positioning Says 10 Best Crypto Tax Software Tools 2026 - Complete Review & Comparison
Sponsored Advertisement Sponsored Ad
news

Coldcard's Weak-Seed Bug Claims a Fourth Wave — Nearly 449 BTC Moved in Hours

A researcher tracking the ongoing Coldcard entropy flaw says a new sweep drained hundreds of bitcoin within roughly two and a half hours, on top of over 1,300 BTC already stolen and left untouched since late July.

Jane Doe

By Jane Doe

Published on Aug 3, 2026

8 min read
Make Cryptorah Icon Cryptorah preferred on Google
Coldcard's Weak-Seed Bug Claims a Fourth Wave — Nearly 449 BTC Moved in Hours

Quick Take

  • Blockchain researcher Alex Thorn flagged a suspected fourth wave of Coldcard-related thefts on August 3, with roughly 449 BTC swept in about two and a half hours.
  • After removing addresses with pre-existing history and stripping out multisig wallets that didn't match the attack's pattern, Thorn narrowed the confirmed-plus-pending total to 448.73 BTC (~$28.1 million) across 709 addresses.
  • Three earlier waves already drained 1,367 BTC (~$85.7 million) from 4,585 addresses, according to Galaxy Research — and none of that money has moved since.
  • The root cause is a weak-entropy flaw in seeds generated on certain Coldcard firmware after March 2021; Coinkite says it has destroyed remaining vulnerable stock and halted shipments.

What Happened

On August 3, blockchain researcher Alex Thorn warned that a fresh round of thefts targeting Coldcard hardware wallets appeared to be underway, with close to 449 BTC swept from hundreds of addresses in roughly two and a half hours. This would mark a fourth wave of attacks tied to the same underlying flaw that has been draining vulnerable Coldcard-generated wallets since late July.

Thorn's more detailed breakdown identified 218 transactions touching 462 suspected victim addresses, spanning Bitcoin blocks 960778 through 969792. Those transactions moved 388.93 BTC — about $24.4 million at the time — into 216 newly created destination addresses, almost none of which had any prior transaction history, a pattern consistent with attacker-controlled wallets rather than normal wallet activity.

Thorn described the addresses as matching the profile of previous Coldcard victims closely enough to give him "high confidence" this is another wave of the same attack, while being careful to note he had no direct confirmation from any victim and was deliberately hedging with the word "likely."

He subsequently revised the figures twice: first removing six addresses that had been transacting long before the Coldcard incident began on July 30 (together accounting for just over 5 BTC), and then stripping out 89 multisig addresses that hadn't appeared in any of the first three waves. That left a surviving core of 709 addresses and 448.73 BTC (about $28.1 million) across both confirmed and still-pending transactions.

Background: what actually caused this

The underlying issue is a weak-entropy vulnerability affecting seeds generated on certain Coldcard firmware versions released after March 2021. Coinkite, the wallet's maker, has confirmed that seeds created on affected Mk3, Mk4, Mk5, and Q devices are exposed. Newer, patched firmware stops the problem for seeds generated going forward, but it cannot retroactively secure seeds that were already generated under the flawed conditions. Coinkite says every single-signature Coldcard address created under those vulnerable conditions will eventually be drained, according to Thorn — which is why the company is urging affected users to migrate to a brand-new seed on an unaffected device rather than simply moving funds within the same compromised wallet.

Why It Matters

Why It Matters

This isn't a one-time hack — it's an ongoing, apparently coordinated drain that has now run in at least four distinct waves since July 30, affecting thousands of addresses generated by a widely used hardware wallet brand. The fact that the funds from the first three waves — 1,367 BTC, worth about $85.7 million — remain unspent in attacker wallets suggests a patient, organized operation rather than smash-and-grab opportunism, and it means the total exposure is still growing as researchers uncover more victims. For anyone who generated a Coldcard seed on an affected device after March 2021, the risk isn't hypothetical or historical — it's active and, per Coinkite's own assessment, effectively inevitable unless funds are moved to a new, unaffected seed.

The Numbers

~449 BTC Swept in Wave 4 per Thorn's initial ~2.5-hour read
448.73 BTC Revised Wave 4 total (confirmed + pending), ~$28.1M
709 Surviving victim addresses after adjustments
1,367 BTC Total from Waves 1–3, ~$85.7M, still unspent (Galaxy Research)
BTC drained by wave

1,367 BTC Waves 1–3 (~$85.7M, unspent)

448.73 BTC Wave 4 (~$28.1M, confirmed + pending)

BTC amounts as reported by researcher Alex Thorn and Galaxy Research. Wave 4 figure is the revised total after Thorn removed non-matching addresses.

⚠️ Flagged: figures don't fully reconcile

The source material gives three different numbers for Wave 4 that don't line up cleanly: an initial ~449 BTC "swept" figure, a separately reported 388.93 BTC actually moved in the 218 identified transactions, and a final revised 448.73 BTC after adjustments. These appear to reflect a live, evolving analysis (Thorn was revising his own count in real time) rather than a single settled figure — treat 448.73 BTC as the most refined number available, but be aware the raw content itself does not resolve the discrepancy.

Methodology & sourcing notes
  • All figures originate from on-chain analysis by researcher Alex Thorn, cross-referenced in part with Galaxy Research's tally of the first three waves.
  • Thorn explicitly labeled Wave 4 victims as "likely" rather than confirmed, since he had no direct victim confirmation at the time of writing.
  • USD values are described as being calculated "at current rates" in the source, without a specified exchange rate or timestamp — treat them as approximate.

Market Reaction

The raw material provided does not include bitcoin price data, trading volumes, or sentiment indicators, so no market-reaction figures can be reported here. The only monetary detail available is that stolen BTC amounts were converted to USD "at current rates" without a specified price point.

⚠️ Flagged: no market data in source

Any commentary on how bitcoin's price or broader market sentiment has responded to this news would be speculative, since the source content contains none of that information. This section is intentionally left thin rather than filled with invented context.

What's Next / Things to Watch

  • The RBF window. Thorn noted that some pending Wave 4 transactions have Replace-by-Fee enabled, meaning victims whose transactions are still sitting unconfirmed in the mempool may have a brief opportunity to outbid the attacker with a higher fee and reclaim their funds before confirmation.
  • Whether stolen funds start moving. The 1,367 BTC from the first three waves has sat untouched in attacker wallets since it was stolen — any movement of those funds would be a significant development.
  • Recovery attempts through exchanges and platforms. One victim holding close to 30 BTC had 17 BTC routed through ThorChain into the Duel online casino; Duel reportedly told the victim it would need a police report filed before considering a freeze. How that situation resolves may set a precedent for other victims trying to recover funds via third-party platforms.
  • Migration compliance. Coinkite is urging all affected users to move to a newly generated seed on an unaffected device. Given Thorn's warning that every vulnerable single-sig address will eventually be drained, the pace at which remaining holders migrate could determine how much more is lost in subsequent waves.
  • Law enforcement progress. Coinkite says it is working with customers and law enforcement to identify those responsible; no outcome has been reported yet.

FAQs

What is the Coldcard vulnerability?

It's a weak-entropy flaw affecting seeds generated on certain Coldcard firmware versions released after March 2021, confirmed by maker Coinkite to affect Mk3, Mk4, Mk5, and Q devices. Weak entropy means the seed-generation process was predictable enough that attackers could reconstruct private keys.

How much bitcoin has been stolen in total?

Based on the source data: the first three waves took 1,367 BTC (~$85.7 million) from 4,585 addresses, per Galaxy Research, and remain unspent. The fourth wave added a revised total of 448.73 BTC (~$28.1 million) across 709 addresses, per Alex Thorn's latest analysis. ⚠️ Note the figures for Wave 4 shifted during Thorn's own live analysis, so 448.73 BTC should be read as the most refined figure available, not a final confirmed number.

What should Coldcard owners do right now?

According to Coinkite's guidance in the source material, affected users should immediately move funds off vulnerable devices and migrate to a newly generated seed on an unaffected device — not just transfer funds within the same compromised wallet. Thorn also recommended using higher transaction fees when moving funds.

Can victims still recover funds mid-transaction?

Possibly, in a narrow window. Thorn noted that some pending Wave 4 transactions have Replace-by-Fee (RBF) enabled, which could let a victim submit a higher-fee replacement transaction to redirect their own funds before the attacker's transaction confirms — but this only works while the transaction is still unconfirmed in the mempool.

Has Coinkite responded?

Yes. Coinkite has confirmed which device lines are affected, destroyed its remaining vulnerable inventory, halted shipments, and says it is working with customers and law enforcement to identify those responsible.

Sourcing note: the original report referenced related coverage by headline only (e.g. on prior BTC-sweep incidents and broader 2026 crypto-security statistics), but did not provide URLs for those pieces, so no source links are included here to avoid inventing citations.

Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.

Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.

Sponsored Advertisement Sponsored Ad
Jane Doe

About Jane Doe

Jane Doe is a senior blockchain journalist covering DeFi, Bitcoin, and web3 innovations since 2018.