A fourth wave of attacks targeting Coldcard hardware wallet users has compromised approximately 448 BTC, according to Galaxy Digital research head Alex Thorn. The exploit targets a specific vulnerability in Coldcard devices, marking an escalation in what appears to be a coordinated assault against the popular cold storage platform.
Thorn highlighted that affected users face a critical window to recover funds before stolen bitcoin moves to exchanges or gets mixed through privacy protocols. Unconfirmed transactions in the mempool offer a narrow opportunity for intervention, though the timeline remains tight. The exact technical vector enabling these attacks remains under investigation, but security researchers point to potential firmware vulnerabilities or supply chain compromise as likely culprits.
Coldcard, manufactured by Coinkite, ranks among the most trusted hardware wallets in institutional and retail circles. The device gained popularity for its emphasis on air-gapped security and open source design. This series of attacks raises serious questions about the hardware wallet's current security posture and whether previous patches adequately addressed exploitable flaws.
Prior attack waves targeting Coldcard users have suggested attackers possess either insider knowledge of the device's architecture or discovered a zero-day vulnerability that circumvents standard security layers. The 448 BTC haul across this fourth attack wave equals roughly $21 million at current prices, indicating sophisticated threat actors with substantial resources.
Galaxy Digital's public warning signals the scale now demands industry-wide attention. Hardware wallet manufacturers face mounting pressure to issue transparent security audits and firmware updates. Users holding Coldcard devices should immediately verify their seed phrases remain secure and consider moving high-value holdings to alternative custodial arrangements pending resolution.
The incident underscores a persistent tension in self-custody arrangements. Even offline devices remain vulnerable to determined attackers exploiting supply chain weaknesses or undisclosed protocol flaws. Institutions and major hodlers may shift allocation toward multi-signature setups or regulated custody solutions until Coinkite resolves the underlying vulnerability.
