A suspected fourth wave of coordinated attacks targeting users of the Coldcard hardware wallet has drained 448 Bitcoin from affected holders, with Galaxy Research head Alex Thorn sounding a public alarm that some victims may still have a narrow window to intervene before all losses are finalized on-chain.
Thorn's warning centers on the fact that a portion of the malicious transactions remain unconfirmed at the time of disclosure. In the Bitcoin network, a transaction that has been broadcast but not yet included in a mined block exists in a pending state within the mempool — and under certain conditions, the original wallet owner may be able to broadcast a conflicting transaction using a higher fee to displace the attacker's outgoing transfer. This Replace-by-Fee mechanism, while not guaranteed to succeed, represents the last meaningful technical recourse available to any Coldcard user who discovers their funds are in motion before a block confirmation locks the theft permanently into the blockchain ledger.
The designation of this event as a "fourth wave" is itself significant. Repeated attack campaigns targeting a specific hardware wallet product suggest either a persistent, unpatched vulnerability within the Coldcard ecosystem, a social-engineering vector that continues to expose users, or a supply-chain compromise that has affected multiple device batches over time. The pattern of successive waves implies a threat actor — or group of actors — with sustained access to an exploitation method that has not been fully neutralized between incidents.
Hardware wallets have long been marketed as the gold standard of self-custody security in the digital asset space, offering air-gapped transaction signing that keeps private keys physically isolated from internet-connected environments. The premise is straightforward: without network exposure, remote theft becomes theoretically impossible. Yet the Coldcard attack series, if confirmed in its fourth iteration, represents a serious challenge to that assurance. When 448 Bitcoin — a sum worth tens of millions of dollars at current market prices — can be extracted from devices specifically designed to prevent such outcomes, the implications reach well beyond Coldcard's own user base.
The broader hardware wallet industry will be watching closely. Competitors including Ledger and Trezor have each navigated their own security controversies in recent years, and any confirmed systematic vulnerability in cold storage hardware reinforces the argument that even the most security-conscious retail investors face asymmetric risks when holding significant Bitcoin positions. For institutional custodians, events like this accelerate the case for multi-signature custody arrangements and geographically distributed key management, where no single hardware failure or compromise can result in total asset loss.
Galaxy's decision to surface this warning publicly, rather than routing it exclusively through private channels, reflects the growing responsibility that research arms of large crypto-native financial firms feel toward the wider community. Thorn's alert gives potentially affected users — those who hold Coldcard devices and have noticed unusual pending transactions — actionable intelligence in real time. The value of that transparency is difficult to overstate: every minute between a malicious broadcast and block confirmation is a minute in which an informed user can attempt to reclaim their funds.
For holders who believe they may be affected, the immediate priority is to check whether any outgoing transactions appear in mempool explorers without their authorization, and to consult technical resources on initiating a Replace-by-Fee transaction with sufficient fee priority to outpace the attacker's submission. Time is the critical variable. Once a transaction clears even a single block confirmation, reversal becomes effectively impossible under Bitcoin's immutable settlement model.
What This Means for Self-Custody Security
The Coldcard fourth-wave incident arrives at a moment when self-custody is undergoing a renaissance in adoption, driven by years of exchange collapses and custodial failures that pushed retail and institutional holders alike toward keeping their own keys. The painful irony is that hardware wallets — the very tools designed to make self-custody safe — are now at the center of a multi-wave theft campaign. Regulators, insurers, and security auditors across the digital asset space will be compelled to ask harder questions about the certification standards applied to cold storage hardware, the transparency of firmware update processes, and the adequacy of manufacturer disclosures when vulnerabilities are discovered. Until those questions receive rigorous answers, holders of significant Bitcoin positions must treat even their most trusted hardware with the assumption that no device is unconditionally secure.
Written by the editorial team — independent journalism powered by Codego Press.
Top comments (0)