A suspected fourth wave of attacks against Coldcard-generated Bitcoin wallets swept close to 449 BTC from hundreds of addresses in a few hours on August 3, pushing total suspected losses from a five-year-old firmware flaw past 1,800 BTC. Coinkite has shipped fixed firmware for every affected model, but says patched devices still need entirely new seed phrases to be safe.
Blockchain researcher Alex Thorn tracked the suspected fourth wave of Coldcard hardware wallet attacks on August 3, in which nearly 449 BTC moved out of hundreds of addresses in about two and a half hours. The wave lifts Coldcard's suspected losses to more than 1,800 BTC from over 5,200 potential victim addresses across four attack waves, though Galaxy Research stresses the figures are on-chain estimates rather than confirmed losses.
Fourth wave moves $28 million before confirmation
Thorn's follow-up analysis identified 218 transactions across 462 suspected victim addresses between blocks 960778 and 969792, moving 388.93 BTC into 216 destination addresses, almost all newly created. He then removed six addresses active before the incident's July 30 start and set aside 89 unrelated multisig addresses, narrowing wave four to 709 addresses and 448.73 BTC, worth about $28.1 million.
According to Galaxy Research, Thorn described the flagged wallets as "likely Coldcard victims", cautioning that the figures come from blockchain analysis rather than confirmed device reports. He urged victims to move funds off affected devices and raise transaction fees, noting that some pending transfers have Replace-by-Fee enabled, giving victims a brief window to outbid the attacker before confirmation.
Earlier waves left 1,367 BTC untouched
Galaxy Research has estimated that the first three confirmed waves drained 1,367 BTC, worth about $85.7 million, from 4,585 addresses, funds that remain unspent in attacker-controlled wallets. Wave three alone accounted for 207.7294 BTC of that total, and Galaxy noted that every coin identified across the first three waves traces back to wallets created after block 674,951 in March 2021, when Coinkite shipped the flawed firmware.
A five-year-old entropy bug in the firmware
Coinkite disclosed that the flaw dates to a 2021 firmware migration that folded in a new cryptographic library and mistakenly called a weaker software-based random-number generator from MicroPython instead of Coldcard's hardware generator when creating new wallet seeds. Coinkite estimates that, as a result, seeds on affected Mk2 and Mk3 devices may carry about 40 bits of effective entropy, while Mk4, Mk5 and Q models may carry about 72 bits, versus the intended 128.
The company halted shipments, destroyed its remaining stock of affected devices, and released fixed firmware for every model. Even so, it says installing the update only secures wallets created after the patch — anyone previously affected still needs to generate a new seed phrase and move funds only after a test transaction confirms.
Kraken security chief calls for independent testing
Kraken chief security officer Nick Percoco said the incident should push the industry to stop leaving seed-generation checks solely to manufacturers. He pointed to NIST SP 800-90B and Germany's BSI AIS-31 as existing standards for validating random-number generators and said no comparable independent verification exists for hardware wallets, comparing the gap to the mandatory lab testing already required for payment PIN devices.
Coinkite's postmortem notes the flaw survived code review because its intended hardware generator kept running elsewhere in the firmware, masking that wallet creation had switched to the weaker source.
Sources: CryptoPotato, The Daily Hodl, crypto.news
Trading involves risk.