Update: This article was revised after on-chain tracking was updated, increasing the estimated fourth-wave total to 448.7 BTC across 709 potential victim addresses.
Galaxy Research has identified what it believes may be a fourth wave of transactions linked to the ongoing Coldcard wallet security incident, with nearly 389 Bitcoin moved from hundreds of suspected victim addresses.
Alex Thorn, head of research at Galaxy, said the latest activity involved 218 transactions affecting 462 potential victim addresses. Approximately 448.7 BTC -0.30% was moved within about two and a half hours, worth roughly $24.5 million with Bitcoin trading near $62,900 at the time of reporting.
According to findings shared by Galaxy Research’s Alex Thorn, the suspected wave initially involved 218 transactions connected to 462 potential victim addresses.
The affected addresses have not all been individually confirmed as Coldcard wallets. Thorn said their transaction history, address characteristics and the unusually high rate of transfers closely matched the pattern found in earlier suspected attack waves.
Transaction activity rose sharply
Galaxy’s analysis found an average of 13.8 wallet sweeps per Bitcoin block during the latest activity. That rate was approximately 45 times higher than the level recorded during a control period before the incident.
Rather than sending all stolen funds into one collection wallet, most transactions created a new destination address for each suspected victim. Some of the Bitcoin had already moved again to second-hop addresses, making the flow of funds more difficult to follow.
Additional transactions with similar characteristics were reportedly waiting in Bitcoin’s mempool, suggesting the activity was still continuing when the alert was issued.
Thorn described the addresses as “likely” victims rather than confirmed cases, noting that the conclusion is based on on-chain patterns and the known shape of outputs associated with vulnerable Coldcard-generated wallets.
Earlier waves drained more than 1,367 BTC
Before the latest activity, Galaxy Research had tracked three suspected waves involving 4,585 addresses and approximately 1,367.05 BTC. The first identified wave on July 30 removed 1,082.65 BTC from 1,196 addresses in just 41 minutes.
Two later waves expanded the estimated losses to approximately $88.6 million at the time.
Adding the newly observed 448.7 BTC would take the suspected total across all four waves to roughly 1,756 BTC. That calculation remains provisional because the fourth wave is still under investigation and researchers have not confirmed every address or ruled out overlap with previous datasets.
Firmware flaw weakened wallet seed generation
The incident has been linked to a firmware integration error introduced in 2021. The flaw caused affected Coldcard devices to use a deterministic software-based pseudorandom number generator during wallet seed creation instead of drawing sufficient randomness from the device’s hardware generator.
The incident highlights the risks associated with Bitcoin self-custody when wallet seeds are generated using vulnerable software.
Under certain conditions, an attacker could reproduce possible seed-generation outputs offline and compare the resulting Bitcoin addresses against publicly available blockchain data.
The exposure depends on the firmware installed when the wallet seed was originally created. Updating the device today does not strengthen an existing seed that was generated using vulnerable firmware.
Affected versions reportedly include Coldcard Mk3 firmware from 4.0.1 through 4.1.9, Mk4 and Mk5 versions before 5.6.0, and Coldcard Q versions before 1.5.0Q. Coinkite released patched firmware but advised potentially affected users to create a completely new seed using secure firmware and transfer their Bitcoin to addresses generated from that seed.
Coinkite confirmed the affected firmware and migration requirements in its official Coldcard security advisory.
Users should not restore the old recovery phrase into an updated device and assume the problem has been removed, because the weakness remains attached to the original seed.
Galaxy has also urged users who may be affected to move their funds promptly and report relevant transaction information to investigators. Where a suspected attacker transaction remains unconfirmed and supports replacement, the legitimate wallet owner may have a narrow opportunity to submit a conflicting transaction with a higher fee.
The fourth wave remains suspected rather than fully confirmed, and the total amount affected may change as researchers review additional transactions.
This is a developing story and may be updated as further information becomes available.
Disclaimer
This content is for informational purposes only and does not constitute financial advice.


