Coldcard's Weak-Seed Bug Claims a Fourth Wave — Nearly 449 BTC Moved in Hours
A researcher tracking the ongoing Coldcard entropy flaw says a new sweep drained hundreds of bitcoin within roughly two and a half hours, on top of over 1,300 BTC already stolen and left untouched since late July.
By Jane Doe
Published on Aug 3, 2026
Quick Take
- Blockchain researcher Alex Thorn flagged a suspected fourth wave of Coldcard-related thefts on August 3, with roughly 449 BTC swept in about two and a half hours.
- After removing addresses with pre-existing history and stripping out multisig wallets that didn't match the attack's pattern, Thorn narrowed the confirmed-plus-pending total to 448.73 BTC (~$28.1 million) across 709 addresses.
- Three earlier waves already drained 1,367 BTC (~$85.7 million) from 4,585 addresses, according to Galaxy Research — and none of that money has moved since.
- The root cause is a weak-entropy flaw in seeds generated on certain Coldcard firmware after March 2021; Coinkite says it has destroyed remaining vulnerable stock and halted shipments.
What Happened
On August 3, blockchain researcher Alex Thorn warned that a fresh round of thefts targeting Coldcard hardware wallets appeared to be underway, with close to 449 BTC swept from hundreds of addresses in roughly two and a half hours. This would mark a fourth wave of attacks tied to the same underlying flaw that has been draining vulnerable Coldcard-generated wallets since late July.
Thorn's more detailed breakdown identified 218 transactions touching 462 suspected victim addresses, spanning Bitcoin blocks 960778 through 969792. Those transactions moved 388.93 BTC — about $24.4 million at the time — into 216 newly created destination addresses, almost none of which had any prior transaction history, a pattern consistent with attacker-controlled wallets rather than normal wallet activity.
Thorn described the addresses as matching the profile of previous Coldcard victims closely enough to give him "high confidence" this is another wave of the same attack, while being careful to note he had no direct confirmation from any victim and was deliberately hedging with the word "likely."
He subsequently revised the figures twice: first removing six addresses that had been transacting long before the Coldcard incident began on July 30 (together accounting for just over 5 BTC), and then stripping out 89 multisig addresses that hadn't appeared in any of the first three waves. That left a surviving core of 709 addresses and 448.73 BTC (about $28.1 million) across both confirmed and still-pending transactions.
Background: what actually caused this
The underlying issue is a weak-entropy vulnerability affecting seeds generated on certain Coldcard firmware versions released after March 2021. Coinkite, the wallet's maker, has confirmed that seeds created on affected Mk3, Mk4, Mk5, and Q devices are exposed. Newer, patched firmware stops the problem for seeds generated going forward, but it cannot retroactively secure seeds that were already generated under the flawed conditions. Coinkite says every single-signature Coldcard address created under those vulnerable conditions will eventually be drained, according to Thorn — which is why the company is urging affected users to migrate to a brand-new seed on an unaffected device rather than simply moving funds within the same compromised wallet.
Why It Matters
Why It Matters
This isn't a one-time hack — it's an ongoing, apparently coordinated drain that has now run in at least four distinct waves since July 30, affecting thousands of addresses generated by a widely used hardware wallet brand. The fact that the funds from the first three waves — 1,367 BTC, worth about $85.7 million — remain unspent in attacker wallets suggests a patient, organized operation rather than smash-and-grab opportunism, and it means the total exposure is still growing as researchers uncover more victims. For anyone who generated a Coldcard seed on an affected device after March 2021, the risk isn't hypothetical or historical — it's active and, per Coinkite's own assessment, effectively inevitable unless funds are moved to a new, unaffected seed.
The Numbers
⚠️ Flagged: figures don't fully reconcile
The source material gives three different numbers for Wave 4 that don't line up cleanly: an initial ~449 BTC "swept" figure, a separately reported 388.93 BTC actually moved in the 218 identified transactions, and a final revised 448.73 BTC after adjustments. These appear to reflect a live, evolving analysis (Thorn was revising his own count in real time) rather than a single settled figure — treat 448.73 BTC as the most refined number available, but be aware the raw content itself does not resolve the discrepancy.
Methodology & sourcing notes
- All figures originate from on-chain analysis by researcher Alex Thorn, cross-referenced in part with Galaxy Research's tally of the first three waves.
- Thorn explicitly labeled Wave 4 victims as "likely" rather than confirmed, since he had no direct victim confirmation at the time of writing.
- USD values are described as being calculated "at current rates" in the source, without a specified exchange rate or timestamp — treat them as approximate.
Market Reaction
The raw material provided does not include bitcoin price data, trading volumes, or sentiment indicators, so no market-reaction figures can be reported here. The only monetary detail available is that stolen BTC amounts were converted to USD "at current rates" without a specified price point.
⚠️ Flagged: no market data in source
Any commentary on how bitcoin's price or broader market sentiment has responded to this news would be speculative, since the source content contains none of that information. This section is intentionally left thin rather than filled with invented context.
What's Next / Things to Watch
- The RBF window. Thorn noted that some pending Wave 4 transactions have Replace-by-Fee enabled, meaning victims whose transactions are still sitting unconfirmed in the mempool may have a brief opportunity to outbid the attacker with a higher fee and reclaim their funds before confirmation.
- Whether stolen funds start moving. The 1,367 BTC from the first three waves has sat untouched in attacker wallets since it was stolen — any movement of those funds would be a significant development.
- Recovery attempts through exchanges and platforms. One victim holding close to 30 BTC had 17 BTC routed through ThorChain into the Duel online casino; Duel reportedly told the victim it would need a police report filed before considering a freeze. How that situation resolves may set a precedent for other victims trying to recover funds via third-party platforms.
- Migration compliance. Coinkite is urging all affected users to move to a newly generated seed on an unaffected device. Given Thorn's warning that every vulnerable single-sig address will eventually be drained, the pace at which remaining holders migrate could determine how much more is lost in subsequent waves.
- Law enforcement progress. Coinkite says it is working with customers and law enforcement to identify those responsible; no outcome has been reported yet.
FAQs
What is the Coldcard vulnerability?
It's a weak-entropy flaw affecting seeds generated on certain Coldcard firmware versions released after March 2021, confirmed by maker Coinkite to affect Mk3, Mk4, Mk5, and Q devices. Weak entropy means the seed-generation process was predictable enough that attackers could reconstruct private keys.
How much bitcoin has been stolen in total?
Based on the source data: the first three waves took 1,367 BTC (~$85.7 million) from 4,585 addresses, per Galaxy Research, and remain unspent. The fourth wave added a revised total of 448.73 BTC (~$28.1 million) across 709 addresses, per Alex Thorn's latest analysis. ⚠️ Note the figures for Wave 4 shifted during Thorn's own live analysis, so 448.73 BTC should be read as the most refined figure available, not a final confirmed number.
What should Coldcard owners do right now?
According to Coinkite's guidance in the source material, affected users should immediately move funds off vulnerable devices and migrate to a newly generated seed on an unaffected device — not just transfer funds within the same compromised wallet. Thorn also recommended using higher transaction fees when moving funds.
Can victims still recover funds mid-transaction?
Possibly, in a narrow window. Thorn noted that some pending Wave 4 transactions have Replace-by-Fee (RBF) enabled, which could let a victim submit a higher-fee replacement transaction to redirect their own funds before the attacker's transaction confirms — but this only works while the transaction is still unconfirmed in the mempool.
Has Coinkite responded?
Yes. Coinkite has confirmed which device lines are affected, destroyed its remaining vulnerable inventory, halted shipments, and says it is working with customers and law enforcement to identify those responsible.
Sourcing note: the original report referenced related coverage by headline only (e.g. on prior BTC-sweep incidents and broader 2026 crypto-security statistics), but did not provide URLs for those pieces, so no source links are included here to avoid inventing citations.
Investment disclaimer: The content reflects the author’s personal views and current market conditions. Please conduct your own research before investing in cryptocurrencies, as neither the author nor the publication is responsible for any financial losses.
Ad Disclosure: This site may feature sponsored content and affiliate links. All advertisements are clearly labeled, and ad partners have no influence over our editorial content.