Coldcard Loss Estimate Rises to $114M as Fourth Bitcoin Sweep Emerges
- The estimated loss from Coldcard-linked Bitcoin sweeps has risen to approximately $114 million, affecting around 1,816 BTC across over 5,200 addresses.
- Affected users should check for unconfirmed transactions in the mempool to potentially replace malicious spends using the replace-by-fee (RBF) feature.
- Users of vulnerable Coldcard firmware must create a new seed with updated firmware to secure their funds, as existing seeds remain at risk.
The estimated scale of the Coldcard-linked Bitcoin sweeps climbed from about $70 million to roughly $114 million on Monday, August 3, after researchers flagged a possible fourth attack wave. The cumulative estimate now stands near 1,816 BTC from more than 5,200 addresses.
That marks a substantial expansion from the 1,082.65 BTC and 1,196 addresses covered in the Friday report, rather than a repetition of the same findings. However, the newer totals remain provisional because much of the activity was identified through transaction-pattern matching rather than direct reports from every affected wallet owner.
Fourth Wave Broadens Suspected Scope
🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW
THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS
pattern identified:
blocks…— Alex Thorn (@intangiblecoins) August 3, 2026
Galaxy Research’s latest mapping initially identified 218 transactions affecting another 462 addresses across blocks 960,778 through 960,792. The activity began early Monday and followed three earlier sweep waves observed since July 30.
Researchers said the newest transactions used fresh destination addresses, frequently assigning one address per suspected victim. That differs from the more concentrated collection pattern seen in the first waves and makes the newer activity harder to group conclusively on-chain.
The revised figures indicate that the incident may now extend far beyond the address set documented on Friday. Still, the 1,816 BTC estimate should not be treated as a confirmed victim-loss total until more transactions are validated or wallet owners report matching losses.
Replace-by-Fee Creates a Rescue Window
The most consequential change is that the attacker reportedly enabled Bitcoin’s replace-by-fee, or RBF, function on the latest transactions. RBF allows an unconfirmed transaction to be replaced by a conflicting transaction that pays a sufficiently higher fee.
Affected users who identify a malicious spend while it remains in the mempool may therefore have a brief opportunity to broadcast a competing transfer to a secure wallet. The window closes once the attacker’s transaction confirms, and successful replacement is not guaranteed.
Galaxy Research published the warning while transactions were still pending, prioritizing speed over confirmation from individual victims.
Single-Key Seeds Remain the Main Risk
The observed sweeps continue to point toward single-signature wallets generated from affected Coldcard firmware. Researchers have not identified the same pattern in multisignature setups, where compromising one seed is generally insufficient to authorize a transfer.
Coinkite has released corrected firmware for affected models, but installing an update does not repair an existing vulnerable seed. Users exposed to the flawed generation process must create a fresh seed using fixed firmware and migrate their funds.
The next verifiable development will be whether the remaining RBF-enabled transactions confirm and whether additional victim reports change the estimated BTC and address totals.
