The Coldcard hardware wallet hack has grown to $116 million (potentially more) across four separate waves, and Coinkite says the last three days have been among the hardest in the company’s history.
Key Takeaways
The Coldcard hack has stolen 1,816 BTC, worth about $116 million, from 5,200+ addresses.Galaxy Research says Wave 4’s sweep rate hit 45 times the pre-incident baseline on August 3.Coinkite urges Coldcard users to move funds immediately after a 2021 firmware RNG flaw.The company’s head Alex Thorn described the latest activity as a probable “fourth organized wave” of thefts, pointing to a sweep rate of 13.8 transfers per block against a pre-incident control window of just 0.3 transfers per block, or roughly 45 times normal baseline activity.
Thorn’s analysis suggests the pattern points to multiple groups racing in parallel across the vulnerable key space rather than a single attacker methodically expanding their operation, a detail that matters because it implies the theft could continue in bursts as different actors independently discover which addresses remain exposed.
Why the Random Number Flaw MattersThe root cause traces back further than this week, as a 2021 firmware update to certain Coldcard devices switched the wallet’s seed-generation process from a strong hardware-based randomness source to a software pattern that turned out to be predictable, meaning any wallet seed created on the affected firmware could, in theory, be guessed rather than brute-forced.
All compromised addresses trace back to wallet seeds generated after the flawed firmware shipped in March 2021, meaning the exposure window has existed for more than five years, quietly, until someone found and began exploiting it this month.
Victims still working through the process have a narrow window to attempt Replace-By-Fee transactions on unconfirmed transfers, though that option only helps if an attacker’s sweep has not already confirmed onchain.


















