Coldcard attack wave: 389 BTC swept in suspected 4th theft

Galaxy research head Alex Thorn warns of a suspected 4th Coldcard attack wave targeting Bitcoin hardware wallets. In an X post, Thorn flagged 218 transactions affecting 462 potential victim addresses over the last few hours, totaling about 388.9 BTC. He said the sweep rate averaged 13.8 sweeps per block—around 45x faster than a pre-incident control window. Most transfers reportedly used a fresh destination address per victim rather than a single collection wallet, with some funds already moved to “second hop” addresses. Thorn noted similar activity in the mempool awaiting confirmation. He said affected users who still hold the relevant keys may be able to broadcast a conflicting higher-fee transaction to move funds to a secure wallet before the attacker’s sweep is confirmed. The attacks follow disclosure of a previously undetected Coldcard firmware flaw that could cause devices to generate wallet seeds with less entropy than intended. Latest estimates cited thousands of impacted wallets and over $90M in stolen BTC, following earlier waves.
Bearish
This is a direct, real-time threat to Bitcoin hardware wallet security, with concrete on-chain evidence (388.9 BTC in a suspected 4th Coldcard attack wave, abnormal sweep rates, and mempool-confirmation risk). Historically, wallet-hack news—even when confined to specific device models—can create short-term bearish pressure: traders may reduce exposure to self-custody flows, and exchanges/OTC demand can rise as holders seek safer custody. In the short term, the mempool component increases urgency and can trigger localized panic selling or rapid fund migrations, especially for users who detect suspicious activity. It can also amplify volatility around BTC because every confirmed sweep increases perceived tail risk for “unmonitored” UTXOs. In the long term, the market impact depends on remediation (firmware updates, user guidance, and attacker identification). If mitigations are credible, the bearish impulse can fade as confidence in affected workflows returns. However, because this appears to be a repeated/iterative exploit (a “4th wave”), traders may price in ongoing security uncertainty and remain more risk-averse until fresh auditing or patch verification reduces the probability of further waves.