Researchers Flag Possible Fourth Coldcard Attack Wave as Investigation Expands

Fresh on-chain activity suggests the Coldcard wallet exploit may still be unfolding, prompting researchers to issue another warning to potentially affected Bitcoin holders.
Summary:
- Security researchers have identified a possible fourth wave of Bitcoin wallet sweeps linked to the Coldcard firmware vulnerability.
- The latest findings rely on blockchain analysis rather than confirmed reports from wallet owners.
- Several suspicious transactions remain unconfirmed, leaving a narrow window for some users to intervene using Replace-by-Fee (RBF).
- Coldcard users with potentially affected wallets are being urged to migrate funds immediately.
The investigation into the recently disclosed Coldcard seed-generation vulnerability is continuing to evolve, with blockchain security researchers reporting another cluster of suspicious Bitcoin transfers that closely resembles previously confirmed exploits.
another update here and thanks to my friends at @nunchuk_io for flagging
my wave 4 set (both confirmed and mempool) in the pastebins in the thread above erroneously contained multisigs. there are ZERO multisigs in waves 1-3
IMPACT ON WAVE 4:
as circulated 857 addrs /…— Alex Thorn (@intangiblecoins) August 3, 2026
Unlike the first three attack waves, the latest activity has not been verified through direct reports from affected wallet owners. Instead, researchers say the warning is based on a combination of transaction structure, wallet history and blockchain activity that matches earlier confirmed attacks.
Researchers Identify Another Suspicious Sweep Pattern
The latest activity was detected across Bitcoin blocks 960,778 through 960,792, representing roughly two and a half hours of blockchain activity. The Details were shared by Alex Thorn in X.
According to the researchers, the suspected wave included:
- 218 transactions
- 462 likely victim addresses
- 216 newly created destination wallets
- Approximately 388.93 BTC transferred
- Sweep activity averaging 13.8 transactions per block, compared with roughly 0.3 per block before the exploit became public
- Every transaction spent outputs generated after the affected Coldcard firmware period
- Nearly every wallet transferred funds to a unique destination address instead of a common collection wallet
Some Bitcoin has already been forwarded to secondary addresses, suggesting at least part of the operation is continuing beyond the initial sweep
While none of those indicators independently confirms a compromise, researchers say the combination closely mirrors the behavior observed during the earlier confirmed exploit waves.
Why Investigators Believe the Wallets Are Connected
The latest addresses were not identified through user reports but through blockchain heuristics.
Researchers said the wallets share several characteristics with previously compromised Coldcard wallets, including the age of the spent outputs, the timing of the transfers and the consistent one-to-one sweep pattern that has become a recurring feature of the campaign.
For that reason, the latest addresses are being classified as “likely” victims rather than confirmed cases until additional evidence becomes available.
Dataset Updated After Review
The investigation has already been refined as additional data became available.
Following a review with wallet provider Nunchuk, researchers removed multisignature wallets that had mistakenly been included in the original dataset.
The revised figures now show:
- Originally identified: 857 addresses holding 486.11 BTC
- Multisignature wallets removed: 89 addresses containing 20.58 BTC
- Current dataset: 709 likely affected addresses holding approximately 448.73 BTC
Researchers noted that no multisignature wallets were identified during the first three confirmed attack waves, making the correction unique to the latest analysis.
A Limited Opportunity May Still Exist
Several suspicious transactions remain unconfirmed in the Bitcoin mempool.
Researchers noted that some previously observed transactions were broadcast with Replace-by-Fee (RBF) enabled, meaning affected users may still be able to replace pending transactions with higher-fee transfers that move their Bitcoin to secure wallets before an attacker’s transaction is confirmed.
Because confirmation times vary, that opportunity may disappear quickly.
Background: Why Coldcard Users Are Being Warned
The latest findings build on the recently disclosed firmware vulnerability affecting seed generation on certain Coldcard devices.
Researchers previously concluded that the flaw reduced the randomness used when creating wallet recovery phrases under specific conditions. Although firmware updates prevent vulnerable wallets from being generated in the future, they do not secure recovery phrases that were already created using affected firmware.
As a result, security researchers continue to recommend generating an entirely new wallet and transferring funds rather than relying solely on firmware updates.
The Investigation Is Still Developing
The latest wallet cluster remains an active investigation rather than a confirmed list of compromised wallets.
Even so, researchers say the recurring transaction patterns, elevated sweep activity and continuing appearance of similar transactions in the mempool suggest the exploitation campaign may still be unfolding. Until more evidence emerges, Coldcard users whose wallets were created during the affected firmware period are being encouraged to assume they could be at risk and migrate funds as a precaution.
The information presented in this article is intended for informational purposes only and should not be interpreted as financial, investment, or trading advice. Coinspress.com does not promote or advocate for any particular investment strategy, asset, or cryptocurrency project. Cryptocurrency markets are highly volatile and unpredictable – always perform your own research and seek guidance from a qualified financial professional before making any investment decisions.











