The Coldcard attack wave 4, by the numbers
A fourth attack wave hit Coldcard wallets over the weekend into Monday, pulling roughly 388.9 BTC out of victim addresses in an initial sweep that grew to about 448.7 BTC as researchers kept tracking new transactions, sourced from somewhere between 462 and 709 newly identified addresses. That's four separate attackers in five days — Wednesday, July 30 through today, Monday, August 3 — draining the same underlying population of vulnerable devices. The running total has climbed from the roughly $88.6 million figure that circulated a few days ago to somewhere near 1,800 BTC cumulative, or about $114-118 million, depending on which snapshot and price you use. Wave 4 also introduced something new: the attacker used replace-by-fee, a mempool technique that lets a transaction be resent with a higher fee to jump the queue. That let some victims race the attacker's own withdrawal in real time, occasionally winning back funds before the theft confirmed. It's a tactical escalation, not a sign the attacker is running out of targets.
Why the vulnerable pool keeps growing
The root cause is a 2021 firmware bug that weakened the randomness Coldcard used to generate seed phrases. On the older Mk2 and Mk3 models, affected seeds carry roughly 40 bits of real entropy instead of the intended 128; on Mk4, Mk5 and the Q, it's closer to 72 bits. Low entropy means the space of possible seed phrases is small enough that an attacker with enough compute can brute-force guesses until one matches a real wallet — no phishing, no malware, no mistake by the owner required. The bug was fixed in later firmware, but that fix did nothing to protect seeds generated before it, because the seed itself was already predictable the moment it was created. That's the mechanism behind four straight waves: each attacker is independently working through the same fixed population of weak seeds, and every few days one of them finds another batch. Neither Coinkite, the maker of Coldcard, nor Galaxy Research, which has been tracking the drains, has published a bounded count of how many affected seeds remain unmigrated. Until one of them does, "how many more waves are coming" doesn't have an answer.
Is my Coldcard still at risk now that wave 4 has hit?
If your device generated its seed before Coinkite's fix and you haven't moved funds to a fresh, post-fix seed, the honest answer is yes — treat it as compromised until you've migrated, not as safe until proven otherwise. That's a harder line than the more cautious framing used earlier in this saga, when it looked plausible the affected population was small and mostly already picked over. Four waves in five days, each surfacing hundreds of new addresses nobody had flagged before, is evidence against that. The device itself isn't being hacked in real time — nothing new is happening to your Coldcard sitting on your desk — the risk is entirely in whether the seed it already holds was ever strong enough to withstand brute-forcing. If you're not certain your seed postdates the RNG fix, the safer move is to generate a new seed on updated firmware and sweep funds across, rather than wait for Coinkite or Galaxy to tell you whether you were in the exposed batch.
Where is the stolen bitcoin going?
The broader market effect is a shift in where bitcoin sits, not in its price. Balances held in exchange-tagged wallets rose from about 2.7038 million BTC to roughly 2.715 million coins through the exploit window — around 11,000 coins moving from self-custody into custodial accounts, and that inflow hasn't reversed. Some of that is stolen funds landing on exchanges where attackers try to cash out; some of it is nervous Coldcard owners moving their own coins somewhere they consider safer while they figure out if they're exposed. Both read the same way on-chain: capital leaving hardware wallets for custodial ones. That's notable because it cuts against a decade of crypto orthodoxy holding that self-custody is strictly safer than trusting an exchange. Public figures, including Binance's CZ, have pointed to the episode as a reminder that no storage method is fail-safe — CZ posted this week that "even hardware wallets can have bugs" and urged holders not to rely on a single custody method. The precise version of that argument is narrower — this is one vendor's firmware defect, not a flaw in hardware custody as a concept — but the trust damage doesn't stay narrow once it's public.
What should pre-fix owners do now?
The base case is that this stays unresolved for a while longer: absent a bounded, forensically confirmed count from Coinkite or Galaxy Research of exactly which seed ranges are affected and how many have migrated, more waves are plausible, exchange inflows likely keep climbing, and the story doesn't get a clean resolution soon. That flips more optimistic quickly if Coinkite or Galaxy publish that bound — a defined affected range with most of it already moved to safety would shrink the remaining risk to something small and known, and the panic would likely fade fast, since the mechanism is fully understood and the fix is already shipped. It flips more bearish if a fifth wave hits and, as with the first four, turns out to be larger than expected, or if hardware-wallet distrust broadens past Coldcard into other vendors regardless of whether their randomness was ever compromised. Watch for three things over the next few days: any statement from Coinkite or Galaxy attempting to size the affected population, further attack waves or RBF rescue races playing out on-chain, and whether exchange balances keep climbing or start reverting toward self-custody. None of those have resolved yet. Until one does, the practical move for anyone holding a pre-fix Coldcard seed is the same one that got more urgent with each of the last four waves: migrate first, ask questions after.
Sources
- https://www.kucoin.com/news/flash/coldcard-faces-fourth-organized-attack-wave-388-9-btc-stolen-in-14-blocks
- https://www.cryptotimes.io/2026/08/03/coldcard-hack-enters-wave-4-449-btc-swept-live-as-victims-race-to-save-funds/
- https://www.coindesk.com/tech/2026/08/03/coldcard-wallet-losses-may-near-usd114-million-as-possible-fourth-sweep-emerges
- https://www.coindesk.com/markets/2026/08/02/unlike-the-ftx-collapse-the-usd88-million-coldcard-exploit-has-investors-sending-bitcoin-back-to-exchanges
- https://crypto.news/coldcard-pushes-bitcoin-back-to-exchanges-anti-self-custody-trade/
- https://wizardsardine.com/blog/coldcard-rng-vulnerability/
- https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack
- https://cyberinsider.com/coldcard-warns-of-wallet-seed-flaw-as-stolen-amounts-reach-88-6-million/
- https://coindoo.com/coldcard-how-stop-pending-transfers/
- https://www.cryptopolitan.com/coldcard-wallets-drained-four-attack-waves/