Coldcard Wallet Attacks Enter Fourth Wave, Putting 449 BTC at Risk
A suspected fourth wave of attacks targeting vulnerable Coldcard-generated Bitcoin wallets may already be underway, with blockchain researcher Alex Thorn warning on August 3 that almost 449 BTC had been swept from hundreds of addresses in about two and a half hours. The latest activity follows three earlier waves linked to a weak-entropy vulnerability affecting certain Coldcard firmware versions. Thorn identified 218 transactions affecting 462 suspected victim addresses between Bitcoin blocks 960778 and 969792, moving 388.93 BTC (worth about $24.4 million) into 216 destination addresses, almost all newly created with no past transaction history. He expressed high confidence these were Coldcard victims based on transaction patterns. After corrections, the core count stood at 709 addresses and 448.73 BTC ($28.1 million) across confirmed and pending transactions. Thorn urged users to immediately move funds off affected Coldcard devices, use higher transaction fees, and be aware that some pending transactions have Replace-by-Fee (RBF) enabled, offering a brief chance to outbid attackers. Galaxy Research estimated the first three confirmed waves drained 1,367 BTC (about $85.7 million) from 4,585 addresses, with funds remaining unspent in attacker-controlled wallets, suggesting coordinated theft. One victim saw 17 BTC routed through ThorChain into an online casino. The vulnerability affects seeds generated on Coldcard firmware versions released after March 2021, including Mk3, Mk4, Mk5, and Q devices. Coinkite, the wallet maker, confirmed the issue, destroyed vulnerable inventory, halted shipments, and is working with customers and law enforcement. Users are advised to migrate to a new seed on an unaffected device, as every single-signature Coldcard address generated under vulnerable conditions is at risk.
Source: https://cryptopotato.com/coldcard-wallet-attacks-enter-fourth-wave-putting-449-btc-at-risk/