Coldcard wallet losses may near $114 million as possible fourth sweep emerges
The pending transactions signal replace-by-fee, so anyone who spots their address in the mempool has minutes to pay a higher fee and move funds first.
A fourth wave of attacks against bitcoin addresses generated by the Coldcard cold wallet has emerged, raising potential losses to nearly $114 million. Researchers discovered that victims can override unconfirmed transactions, allowing them to move funds out. The attack began on July 30 and has affected 5,200 addresses, totaling 1,816 bitcoin.
Coldcard manufacturer Coinkite released emergency firmware to address the issue, instructing users to move funds to fresh wallets. The flaw in the device's firmware stems from a predictable software randomizer used in seed generation, making the keys reproducible offline. The attacker pattern involved 218 transactions across 462 victim addresses, occurring at a rate 45 times higher than normal.
Written by urgent.news from CoinDesk's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- A Coldcard firmware flaw let hackers drain $70 million in Bitcoin in 41 minutes, with losses now topping $88 million techspot.com
- Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen therecord.media
- Coldcard’s 5-year flaw reveals hardware wallet testing gap: Kraken’s security chief cointelegraph.com
- Solo Bitcoin miner nets $200,000 as Coldcard hardware wallet drains rocks sentiment coindesk.com