{"id":76354,"date":"2026-08-04T09:45:42","date_gmt":"2026-08-04T09:45:42","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/the-coldcard-hack-just-hit-116-million-a-fourth-wave-is-still-draining\/"},"modified":"2026-08-04T09:45:42","modified_gmt":"2026-08-04T09:45:42","slug":"the-coldcard-hack-just-hit-116-million-a-fourth-wave-is-still-draining","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/the-coldcard-hack-just-hit-116-million-a-fourth-wave-is-still-draining\/","title":{"rendered":"The Coldcard Hack Just Hit $116 Million. A Fourth Wave Is Still Draining"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">The Coldcard hack has stolen 1,816 BTC, worth about $116 million, from 5,200+ addresses.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Galaxy Research says Wave 4\u2019s sweep rate hit 45 times the pre-incident baseline on August 3.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Coinkite urges Coldcard users to move funds immediately after a 2021 firmware RNG flaw.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<h2>Four Waves in Four Days<\/h2>\n<p>What started as an estimated $30 million theft has more than tripled in less than a week. Bitcoin.com News <a href=\"https:\/\/news.bitcoin.com\/featured\/the-coldcard-exploit-explained-who-lost-bitcoin-and-whos-at-risk\/\">first reported the exploit<\/a> as it emerged, with the figure climbing with each new wave of transactions attackers have pulled from Coldcard-generated wallets: from an initial burst that moved $30 million in the opening ten minutes, to roughly $75 million after a second wave, to nearly $89 million as the theft spread to 4,500 addresses.<\/p>\n<p>The figure now stands at approximately <a href=\"https:\/\/fortune.com\/2026\/08\/03\/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit\/\" target=\"_blank\" rel=\"noopener noreferrer\">$116 million across 1,816 BTC<\/a> pulled from more than 5,200 individual addresses. Galaxy Research, which has tracked the exploit in real time, confirmed a fourth wave on August 3 that alone moved roughly 449 BTC after corrections to earlier figures.<\/p>\n<p>The company\u2019s head Alex Thorn described the latest activity as a probable \u201cfourth organized wave\u201d of thefts, pointing to a sweep rate of 13.8 transfers per block against a pre-incident control window of just 0.3 transfers per block, or roughly 45 times normal baseline activity.<\/p>\n<p><\/p>\n<p>Thorn\u2019s analysis suggests the pattern points to multiple groups racing in parallel across the vulnerable key space rather than a single attacker methodically expanding their operation, a detail that matters because it implies the theft could continue in bursts as different actors independently discover which addresses remain exposed.<\/p>\n<h2>Why the Random Number Flaw Matters<\/h2>\n<p>The root cause traces back further than this week, as a 2021 firmware update to certain Coldcard devices switched the wallet\u2019s seed-generation process from a strong hardware-based randomness source to a software pattern that turned out to be predictable, meaning any wallet seed created on the affected firmware could, in theory, be guessed rather than brute-forced.<\/p>\n<p>During the early scramble, <a href=\"https:\/\/news.bitcoin.com\/security\/zachxbt-declines-trace-coldcard-hack\/\">ZachXBT declined to help trace<\/a> the stolen funds, leaving victims and independent researchers racing against attackers who already understood exactly which addresses were vulnerable.<\/p>\n<p>That head start is why the largest wallets were hit first. <a href=\"https:\/\/news.bitcoin.com\/security\/coldcard-attacker-stole-30m-in-10-minutes-by-targeting-big-wallets\/\">Attackers targeted the biggest balances<\/a> within minutes of the exploit becoming active, and within roughly 25 minutes had already pulled hundreds of bitcoin from single-signature wallets before most holders had any indication their funds were at risk.<\/p>\n<p>All compromised addresses trace back to wallet seeds generated after the flawed firmware shipped in March 2021, meaning the exposure window has existed for more than five years, quietly, until someone found and began exploiting it this month.<\/p>\n<h2>Coinkite\u2019s Response and What Comes Next<\/h2>\n<p>Coinkite, the Canadian manufacturer behind Coldcard, has acknowledged the scale of the damage directly. In a statement addressing the ongoing thefts, the <a href=\"https:\/\/fortune.com\/2026\/08\/03\/bitcoin-owners-116-million-hack-coldcard-coinkite-exploit\/\" target=\"_blank\" rel=\"noopener noreferrer\">company said<\/a> \u201cthe last three days have been some of the hardest in this company\u2019s history, and for a lot of the people reading this, they\u2019ve been something much worse,\u201d and strongly advised anyone who generated a wallet seed on a Coldcard device to move their funds to a new, safely generated wallet as soon as possible.<\/p>\n<p>Victims still working through the process have a narrow window to attempt Replace-By-Fee transactions on unconfirmed transfers, though that option only helps if an attacker\u2019s sweep has not already confirmed onchain.<\/p>\n<p>Lastly, industry personnel like Anthony Pompliano have pushed back on the narrative that the hack was on bitcoin itself, arguing that the <a href=\"https:\/\/news.bitcoin.com\/security\/bitcoin-wasnt-hacked-in-coldcard-attack-pompliano-explains\/\">flaw sat squarely in Coldcard\u2019s firmware<\/a> rather than the BTC protocol.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/security\/coldcard-hack-116-million-fourth-wave\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways The Coldcard hack has stolen 1,816 BTC, worth about $116 million, from 5,200+ addresses. Galaxy Research says Wave 4\u2019s sweep rate hit 45 times the pre-incident baseline on August 3. Coinkite urges Coldcard users to move funds immediately after a 2021 firmware RNG flaw. Four Waves [&hellip;]<\/p>\n","protected":false},"author":3947362404,"featured_media":76355,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/76354"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/3947362404"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=76354"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/76354\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/76355"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=76354"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=76354"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=76354"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}