Second Coldcard Wave Hits: 389 BTC Stolen, RBF Offers Last Hope
Key Takeaways
Galaxy Digital’s Alex Thorn identifies a second wave of Coldcard exploits moving nearly 389 BTC. Users with unconfirmed transactions may use Replace-by-Fee (RBF) to redirect funds, though confirmed sweeps are irreversible.
Woofun AI reports that a second wave of targeted attacks against Coldcard wallet users emerged around 1:00 UTC on August 3, identified by Galaxy Digital’s Managing Director and Head of Firmwide Research, Alex Thorn. This incident occurred just days after the initial wave was reviewed, marking a rapid escalation in exploitation efforts against the hardware wallet ecosystem. The timing suggests a coordinated campaign leveraging known vulnerabilities before widespread mitigation could be deployed.
The scope of the onchain review conducted by Thorn covered Bitcoin blocks 960,778 through 960,792, a range spanning approximately two and a half hours of intense activity. This specific block interval was selected because the malicious activity was still ongoing when the findings were published, capturing the peak of the exploit window. The analysis focused on this narrow temporal slice to isolate the attack vector from normal network noise.
Statistical breakdown of the cluster revealed 218 transactions involving 462 suspected victim addresses and 216 previously unused destination addresses. Together, these movements accounted for a total volume of 388.92748828 BTC. The high ratio of unique destination addresses to transactions indicates a deliberate strategy to fragment the stolen assets, complicating immediate identification and aggregation by observers.
With Bitcoin trading near $62,700 at the time of writing, the total amount moved was worth approximately $24.4 million. This figure measures suspected transfers rather than confirmed, irrecoverable losses, as some funds remained in a state of flux. The valuation underscores the significant financial risk posed by firmware-level vulnerabilities in high-value storage solutions.
Woofun AI data shows that Thorn recorded approximately 13.8 suspected sweeps per Bitcoin block during the incident, compared with a baseline of 0.3 per block during a control period before the incident. The observed rate was therefore around 45 times higher than normal activity levels. This statistical anomaly provides strong evidence of coordinated malicious behavior rather than organic user activity.
Technical evidence linking the activity to the Coldcard firmware boundary was robust, with none of the transaction inputs predating the vulnerability’s introduction. Coinkite or law enforcement had not completed a formal investigation, but the pattern matched earlier suspected Coldcard activity. Almost every transaction sent funds to a separate, newly created address, with only one destination receiving two sweeps. This distribution across hundreds of fresh addresses made the cluster less obvious at a glance, avoiding immediate detection by simple heuristics.
The mempool status of these transactions is critical, as some were still waiting for inclusion in a block. An unconfirmed transaction may still be replaceable when it signals Replace-by-Fee, commonly known as RBF. Thorn noted that the confirmed transactions in the cluster had signaled RBF before entering a block, implying that similar transactions still waiting for confirmation may use the same setting. This mechanism allows an unconfirmed transaction to be replaced by another transaction spending the same coins with a higher fee.
Recovery conditions depend on whether the user still controls the relevant private keys and can issue a valid replacement with a higher fee than the attacker’s transaction.
However, recovery is not guaranteed, as the replacement must satisfy Bitcoin’s transaction policies, and the attacker may also increase the fee. The opportunity ends once the unauthorized transaction is confirmed. Thorn found that some of the Bitcoin had already moved from the initial destination addresses into second-hop wallets. A first-hop address receives the original sweep, while a second hop occurs when the Bitcoin is transferred again to another address, confirming the original sweep and removing the possibility of replacing it through RBF.
The Bitcoin remains traceable onchain, although further transfers can divide it among additional addresses, combine it with other funds, or move it toward exchanges and other services. Recovery may then depend on identifying those services and obtaining cooperation from their operators or law-enforcement authorities. Users must preserve the transaction ID, wallet records, and relevant device information for tracing, reporting, and any later investigation if the funds have already been confirmed.
Thorn urged users to act quickly by reviewing their transaction history for outgoing payments they did not authorize. If a suspicious transaction remains unconfirmed and is marked as replaceable, the owner may still be able to issue a higher-fee transaction sending the same Bitcoin to a secure wallet. Anyone unfamiliar with the process should seek urgent assistance from a trusted Bitcoin security professional rather than experimenting with the affected funds. Any remaining Bitcoin should be transferred to a new wallet created with fresh security credentials, as moving funds to another address generated from the same potentially compromised seed would not remove the underlying risk. Users should never provide a seed phrase, private key, wallet backup, or PIN to anyone offering recovery assistance, as those secrets are not required to inspect a public transaction or determine whether it remains unconfirmed.
Comments
No comments yet.