TL;DR
- A fourth wave tied to Coldcard devices pushed Bitcoin losses higher as the theft expanded across more than 5,200 addresses.
- Researchers identified the activity in real time via mempool transactions and Replace-by-Fee signals.
- The attacker’s behavior is evolving, with reduced clustering and early second-hop fund movement.
A fourth wave of Bitcoin theft from Coldcard wallets is underway. And, for the first time in this incident, researchers spotted it while transactions were still sitting unconfirmed in the mempool.
Galaxy Research’s Alex Thorn flagged the activity Monday. He warned that a pattern matching the first three waves was moving through blocks in real time. Early estimates showed hundreds of Bitcoin already moving across hundreds of addresses. The counts were revised multiple times as the sweep progressed. The confirmed portion later settled near 448.7 BTC from 709 suspected victim addresses after removing roughly 89 multisig addresses that did not match earlier patterns. The sweep ran at about 13.8 transactions per block, far above the baseline rate Galaxy measured before the incident began.
Some of the flagged transactions carried Replace-by-Fee signaling. This feature allows a pending transaction to be replaced with a higher-fee version. The transactions had not yet confirmed when Thorn posted, but a subset of affected users had a brief window to broadcast a competing transaction and move their funds before the attacker’s transaction confirmed. It is the first point in the four-wave incident where researchers surfaced a theft while in progress and not just after the fact.
The combined figure now approaches 1,816 BTC swept from more than 5,200 addresses. The estimates build from on-chain clustering based on address activity. It is not a confirmed victim count or a final loss figure.
Three earlier waves set the pattern
According to Coinkite, the Canadian company behind Coldcard, the vulnerability traces to a March 2021 firmware error. It routed wallet seed generation through a predictable software random-number generator instead of the device’s hardware generator. A wallet seed produces the private keys controlling its addresses. A predictable seed leaves a far smaller set of possible keys for an attacker to test offline.
The first theft wave hit on July 30, draining about 1,083 BTC from 1,196 Coldcard addresses in a 41-minute window, close to a full Bitcoin per address. A second wave followed roughly 27 hours later. It added about 76 BTC and brought the running total to 1,158.66 BTC from 2,673 addresses. Galaxy said the two waves shared enough transaction characteristics, common collector addresses, matching output types, and similar timing, to suggest a single operator. However, the company stopped short of calling that confirmed.
A third wave, identified Saturday, added 207.7 BTC from 1,912 addresses and lifted the total to 1,367.05 BTC across 4,585 addresses. It averaged just over a tenth of a Bitcoin per address. Well below the first wave’s average, this suggests the higher-value addresses in the vulnerable pool had already been cleared.
Each wave changed its footprint
The first two waves funneled stolen funds into a small number of shared collector addresses, a pattern that was relatively easy to trace. The third wave broke from that structure. It grouped an average of about six victim addresses per sweep transaction and held the proceeds in more complex script-based addresses, a departure from the earlier simpler format. It then sent each transaction’s proceeds to its own destination instead of a shared collector. Funds spread across roughly 293 separate addresses. The attacker also scanned only the default derivation path, the standard address branch most wallets use first. The two earlier waves had tested several paths.
Wave four extended that anti-clustering approach. Most of its 216 destination addresses were newly created with no prior transaction history. Galaxy also noted that some funds had already moved to second-hop addresses by the time it posted, so one further step was added compared to the earlier waves.
Galaxy is confident each wave is internally the work of one operator, but not that the same operator carried out all four. Waves one and two likely share an operator, based on matching structure and a 27-hour gap between them, though Galaxy stopped short of confirming it. Wave three broke that pattern enough that the company would not assume the same actor was behind it. Wave four looks different again. Thorn’s read is that the wave four topology suggests multiple actors now racing the same key space in parallel, not one operator simply scaling up.
>>> Read more: Developers Targeted in OpenClaw Wallet Theft Scam on GitHub
Fixed firmware does not undo existing exposure
Coinkite has released corrected firmware for every affected Coldcard model and release track, including Mk3, Mk4, Mk5, and the Coldcard Q. The fix addresses future seed generation. It does not strengthen a seed that was already created on the affected software. The underlying private keys do not change when the firmware is updated.
Coinkite’s advisory tells affected owners to generate a new seed on corrected firmware and migrate their funds. It identifies a narrow exception for seeds created with at least 50 independent, private dice rolls entered through the device’s added-entropy feature. It also notes that a strong, unique BIP-39 passphrase adds an independent barrier. Even so, the company continues to recommend migration for passphrase users, since a weak or reused passphrase can still be guessed.
Coinkite has published a technical explanation of the root-cause bug but has not yet released the fuller formal technical review it said would follow its initial advisory. The company has not confirmed the roughly $88.6 million figure tied to the first three waves as a final loss total. Neither has it confirmed the wave four numbers Galaxy published.
What happens next
If any of the parked Bitcoin moves, it stops being a static number on a blockchain explorer and becomes something investigators can follow. Galaxy has already shared roughly 600 suspected attacker addresses with federal investigators, compliance firms, and cross-industry security researchers. Any exchange, mixer, or swap service can already check fund sources against those addresses. That may be exactly why the proceeds from the first three waves have sat untouched for days: moving them costs the attacker(s) the one advantage still working in their favor.
Wave four offers an early look at what that risk looks like in practice. Some of its funds already moved to second-hop addresses within hours of the sweep. It sits closer to needing an eventual exit than anything from the earlier waves. On-chain data alone cannot settle whether the attacker is preparing to cash out or simply adding another layer of obfuscation between the theft and future movements. Where those second-hop funds go next, toward an exchange or a swap service, or into further unlinked addresses, is likely to be the first real signal either way. It is not the only one to watch: Coinkite has yet to publish the fuller technical review it promised after its initial advisory, and the company has not confirmed Galaxy’s wave four figures on its own. Either would sharpen a picture that, for now, still rests on on-chain inference alone.








