🚨 ALERT: ⚠️ Coldcard security incident surpasses $114M after fourth wave of Bitcoin drains
The security incident affecting certain Coldcard hardware wallets continues to expand. According to the latest analysis from Galaxy Research, estimated losses have reached approximately 1,816 bitcoin:native, worth around $114 million, after a fourth wave of unauthorized wallet drains was identified.
The first three waves had already accounted for around 1,367 BTC, impacting more than 4,500 addresses. The latest wave added approximately 449 BTC from hundreds of additional wallets, pushing the total impact above 5,200 affected addresses.
Galaxy Research reported that the attacker continues operating in a systematic and automated manner, targeting additional wallets while using more complex transaction patterns and techniques such as replace-by-fee (RBF) to modify transactions and make tracking more difficult.
The origin of the incident remains linked to a firmware vulnerability identified in 2021, where certain Coldcard devices generated wallet seeds using insufficient randomness, potentially allowing remote reconstruction of private keys without physical access to the hardware.
Coinkite continues advising potentially affected users to migrate funds to new seeds generated with updated firmware and consider additional security measures such as passphrases or multisig setups.
The case has become one of Bitcoin’s largest recent self-custody security tests, highlighting that wallet security depends not only on hardware protection but also on the integrity of the key generation process itself.