Estimated losses from a vulnerability affecting Coldcard hardware wallets have surged toward $114 million as security researchers and blockchain analysts flag the emergence of what may be a fourth wave of malicious fund sweeps.
The escalating damage figure comes amid continued exploitation of a security flaw that has enabled attackers to systematically drain compromised wallets. Multiple waves of attacks have been observed over recent months, with each sweep targeting users who have not yet migrated funds from affected devices or applied necessary security patches.
Blockchain monitoring has revealed pending transactions associated with the suspected fourth wave that signal replace-by-fee (RBF) characteristics, according to CoinDesk. This technical detail carries critical implications for potential victims: anyone who identifies their wallet address in the mempool—the waiting area for unconfirmed transactions—has only minutes to respond. Users can attempt to front-run the attackers by submitting a competing transaction with a higher fee, effectively rescuing their funds before the malicious sweep executes.
The RBF mechanism, originally designed to allow Bitcoin users to adjust transaction fees during network congestion, has been weaponized in this context. Attackers leverage the feature to prepare sweeps that can be expedited once conditions are favorable, but the same mechanism provides a narrow window for alert users to intervene.
The $114 million estimate represents a substantial increase from previously reported figures, underscoring both the scale of the vulnerable address set and the efficiency with which attackers have operationalized their draining infrastructure. The progression through multiple distinct waves suggests a methodical approach to the exploitation, with operators potentially sequencing attacks to maximize extraction while managing blockchain congestion and fee markets.
Coldcard, manufactured by Coinkite, has historically positioned its devices as security-focused options for Bitcoin custody, emphasizing air-gapped operation and minimal attack surface. The current vulnerability represents a significant departure from this reputation, though the specific technical details of the exploit vector have not been fully disclosed in public reporting.
The emergence of a potential fourth wave indicates that despite widespread notification efforts and prior reporting on the vulnerability, a substantial number of affected addresses remain active and susceptible to drainage. This persistence points to challenges in reaching all potentially affected users, particularly those who may have purchased devices through secondary markets or who maintain inactive holdings.
Security practitioners have emphasized that the minutes-long response window identified in mempool monitoring requires active chain surveillance. Automated alerts and mempool monitoring tools have become recommended infrastructure for holders of significant Bitcoin balances, particularly those using hardware wallets from any manufacturer.
The incident joins a growing catalog of hardware wallet security events that have challenged assumptions about physical device invulnerability. While hardware wallets generally isolate private keys from internet-connected systems, implementation flaws, supply chain compromises, and interaction vulnerabilities have repeatedly demonstrated that offline storage alone does not guarantee protection against sophisticated extraction schemes.