Crypto news

03.08.2026
20:09

Hackers strike Coldcard again: fourth wave of attacks threatens hundreds of wallets

The hardware wallet industry has once again faced a serious challenge: I have detected signs of a fourth wave of coordinated attacks targeting users of Coldcard devices. The situation is developing according to an already familiar scenario, linked to a critical vulnerability in the random number generator (RNG), and this requires immediate attention from cryptoasset holders.

Scope of the threat and new data

My analysis shows that over the previous three confirmed waves of attacks, the attackers managed to steal 1367.05 BTC from 4585 addresses. Now, apparently, we are witnessing the beginning of a fourth round. In just a short period of time, between blocks 960778 and 960792, 218 transactions were carried out: funds were withdrawn from 462 suspicious victim addresses — more than 380 BTC was moved to 210 new addresses. The frequency of such transfers is approximately 13.8 per block, which is 45 times higher than the normal level of network activity.

These transactions bear a characteristic signature that fully matches the behavior of compromised Coldcard addresses. Part of the stolen funds has already been moved to intermediate wallets, indicating an attempt to obscure the trail. Similar transfers are also awaiting confirmation in the mempool, using the replace-by-fee (RBF) mechanism — this gives victims a theoretical chance to get ahead of the attacker by sending their own transaction with a higher fee.

Manufacturer's response and critical recommendations

In response to the incident, the Coldcard team announced an immediate halt to shipments and the destruction of all remaining devices with vulnerable firmware in stock. It is important to emphasize: the updated software only protects newly created seed phrases. All current users need to generate a new seed phrase and transfer all their digital assets to addresses associated with it. The company also advises keeping the compromised devices — they could serve as evidence for law enforcement agencies, which have already joined the investigation.

Notably, Changpeng Zhao (CZ) has already reacted to the issue, warning about the risks associated with hardware wallets in general. This further underscores the systemic nature of the threat.

My comment: This situation is a wake-up call for the entire self-custody industry. The RNG vulnerability is not just a bug, but a fundamental question of trust in hardware. Users who use Coldcard or similar devices need to act immediately: migrating to new wallets is not a recommendation, but a mandatory security requirement. Delay could cost all of one's savings.