Suspected 4th Coldcard attack wave sweeps 448 Bitcoin: Galaxys Thorn

abstrak:A new wave of coordinated thefts has hit Coldcard Bitcoin hardware wallet users, days after the first attacks. Galaxys Alex Thorn reported roughly 448.7 BTC moving across 709 potential victim addresses, with sweeping activity about 45 times normal levels. Transfers often used fresh destination addresses per victim, and some funds moved through second-hop addresses. Thorn said the patterns strongly suggest Coldcard victims, noting similar unconfirmed transactions in the mempool. Affected users controlling keys might broadcast a higher-fee conflicting transaction to secure funds before attackers confirm. This follows disclosure of a Coldcard firmware flaw causing low-entropy wallet seeds; latest estimates indicate thousands of wallets impacted and over $90 million in Bitcoin stolen.

Update (Aug. 3 at 4:19 am UTC): This article has been updated with the latest estimated number of affected addresses and Bitcoin from Galaxys Alex Thorn.

Coldcard users are being warned of a new wave of coordinated thefts targeting their Bitcoin hardware wallets, coming just days after the first wave of attacks on Thursday.

In an X post on Monday, Galaxy research head Alex Thorn flagged hundreds of transactions impacting 709 potential victim addresses, moving around 448.7 Bitcoin (BTC).

Thorn said the activity averaged 13.8 sweeps per block, around 45 times the rate observed in a pre-incident control window. Most transfers have seen a fresh destination created for each victim rather than converging on a central collection wallet.

Some funds have already been swept into second hop addresses, he said.

Related: Coldcard Bitcoin loss estimate rises to $70M after Galaxy analysis

“These are LIKELY Coldcard victims — they match the shape of coldcard vulnerable utxos and the elevated transaction pattern gives me high confidence they are another wave of attacks,” said Thorn.

The researcher said there are similar transactions in the mempool waiting to be confirmed. Affected users who control the relevant keys may be able to broadcast a conflicting transaction with a higher fee to move their funds to a secure wallet before the attackers transaction is confirmed.

The activity follows the disclosure of a previously undetected Coldcard firmware flaw that has caused affected devices to generate wallet seeds with less entropy than intended. The latest estimates suggest that thousands of wallets have been impacted, with over $90 million in Bitcoin stolen.

Disclaimer

Ang mga pananaw sa artikulong ito ay kumakatawan lamang sa mga personal na pananaw ng may-akda at hindi bumubuo ng payo sa pamumuhunan para sa platform na ito. Ang platform na ito ay hindi ginagarantiyahan ang kawastuhan, pagkakumpleto at pagiging maagap na impormasyon ng artikulo, o mananagot din para sa anumang pagkawala na sanhi ng paggamit o pag-asa ng impormasyon ng artikulo.
Nakaraang post

Tumaas ng 288% ang tokenized stock trading noong Hulyo, ngunit ONE QQQ token ang nagtulak sa halos lahat ng ito.

Susunod

Bakit itinapon ng isang DeFi platform ang consumer app nito para maging Secret backend para sa mga higanteng tech