What to Know
- A possible fourth wave of sweeps targeting bitcoin in Coldcard-generated addresses began early Monday and was still running hours later.
- Market researchers estimate the attacker has moved about 1,816 bitcoin, or roughly $114 million, from more than 5,200 addresses since July 30.
- The latest pending transactions appear to signal replace-by-fee, meaning victims who identify their address in the mempool may be able to pay a higher fee and move funds first.
- The first wave on July 30 took 1,083 bitcoin from 1,196 addresses in 41 minutes.
- Two additional weekend waves brought observed losses to 1,367 bitcoin across 4,585 addresses before the possible fourth wave.
- The suspected flaw traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer rather than the chip’s hardware randomizer.
- The pattern appears consistent with an issue affecting single-key Coldcard seeds and not multisignature setups.
- Coldcard manufacturer Coinkite released emergency firmware for every affected model and urged users who generated a seed on the flawed software to move funds to an address made with a fresh seed.
Possible Fourth Sweep Raises Urgency for Coldcard Users
A possible fourth wave of bitcoin sweeps targeting Coldcard-generated addresses has intensified concerns around a vulnerability linked to older wallet seed generation. The activity began early Monday and was still underway hours later, with market researchers estimating that total observed movement may have reached about 1,816 bitcoin, or roughly $114 million, from more than 5,200 addresses since July 30.
The latest wave is notable not only because of its scale, but because the transactions appear to have opted into Bitcoin’s replace-by-fee mechanism. That feature allows a pending transaction to be replaced by another transaction spending the same coins if the replacement pays a higher fee. In practical terms, users who spot their funds in the mempool before confirmation may have minutes to respond by broadcasting a competing transaction with a higher fee and moving the bitcoin to a safe address first.
That narrow opening does not remove the severity of the incident. Once a transaction is confirmed, the opportunity to replace it is gone. Bitcoin transactions are designed to be final after confirmation, and a confirmed sweep cannot be reversed by a wallet maker, exchange, miner, or network participant. For affected users, the only meaningful response is rapid detection and immediate action before confirmation.
How the Replace-by-Fee Window Works
The mempool is the queue of unconfirmed Bitcoin transactions waiting to be included in a block. When a transaction sits there, it has not yet become part of the blockchain’s confirmed history. Replace-by-fee, often called RBF, is a standard Bitcoin feature that allows a user to replace an unconfirmed transaction with another version that offers miners a higher fee.
In ordinary use, RBF helps bitcoin users speed up their own delayed payments when network demand rises. In this case, however, the attacker’s apparent use of RBF may create an unusual defensive opportunity. If a victim sees an outgoing transaction from their address in the mempool, they may be able to broadcast a conflicting transaction with a higher fee that sends the funds to a secure wallet they control.
The challenge is speed. The time between broadcast and confirmation can be short, especially when fee conditions favor rapid inclusion in a block. Users must identify the affected address, have access to a safe destination wallet, construct a valid transaction, and set a fee high enough to outbid the pending sweep. For many retail users, that is difficult without technical familiarity or wallet software capable of handling urgent fee replacement.
Observed Waves Began on July 30
The incident began with a sweep on July 30 that took 1,083 bitcoin from 1,196 addresses in 41 minutes. Over the weekend, two more waves increased observed losses to 1,367 bitcoin across 4,585 addresses. The possible fourth wave, if confirmed by the same pattern, would bring the running total to about 1,816 bitcoin, near $114 million, from more than 5,200 addresses.
Those figures underscore how a seed-generation failure can become catastrophic for cold-storage users. Hardware wallets are widely used because they separate private-key handling from internet-connected devices. But the security model depends on strong randomness at the moment a seed is created. If the seed generation process becomes predictable, the resulting private keys may be reproducible by someone who can determine the range of possible outputs.
Market participants tracking the movement have focused on transaction patterns, address behavior, and timing. The latest activity covered blocks 960,778 to 960,792, with 218 transactions hitting 462 victim addresses at a rate of about 14 sweeps per block. That compares with 0.3 in a pre-incident control window, roughly 45 times normal. Such clustering can help distinguish coordinated sweeping from ordinary user activity, though researchers have also emphasized the need to treat rapidly developing findings with caution while funds remain at risk.
Firmware Flaw Traced to March 2021 Build
The suspected vulnerability traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the chip’s hardware randomizer. That distinction matters because seed generation relies on entropy, or unpredictability. A hardware random source is intended to produce values that cannot be feasibly guessed. A predictable software randomizer can narrow the search space and potentially allow an attacker to reproduce keys offline once the relevant range is identified.
Coldcard manufacturer Coinkite has released emergency firmware for every affected model. The company has also told users who generated a seed on the flawed software to move funds to a wallet address created with a fresh seed. In this context, simply updating firmware is not enough if the vulnerable seed has already been generated. A firmware update can correct future behavior, but it cannot make an already compromised or predictable seed safe.
The central security issue is not merely whether a device is currently running updated software. It is whether the seed controlling funds was originally created during the affected conditions. If a seed was created using flawed randomness, any addresses derived from that seed may remain exposed until the funds are moved to a wallet created with a secure new seed.
Single-Key Seeds Appear More Exposed Than Multisignature Setups
The observed pattern appears consistent with a flaw affecting single-key Coldcard seeds rather than multisignature configurations. None of the first three waves touched multisignature setups. That detail is important because multisignature wallets require more than one key to move funds. Even if one seed were exposed, an attacker would still need the additional signing keys required by the multisignature policy.
For long-term bitcoin custody, the distinction reinforces a key lesson: cold storage is not a single design. A single-key hardware wallet can offer strong protection against common online threats, but it remains dependent on one seed. A multisignature setup spreads control across multiple keys and can reduce the risk that one flawed device, seed, or backup compromises the full balance.
That does not mean multisignature is risk-free or appropriate for every user. It introduces operational complexity, including key backups, signer distribution, and recovery planning. But in this incident, the lack of observed multisignature impact aligns with the broader view among technical traders and custody specialists that diversified signing policies can offer resilience when one key source is called into question.
Attacker Behavior Has Shifted
Earlier waves were easier to follow because swept funds moved toward shared collectors. In the latest activity, the attacker appears to be sending funds to fresh addresses with no prior history, one per victim. Fresh destination addresses make tracing more difficult because there is less historical behavior to connect them to prior clusters.
The pattern also included six destination addresses with years of prior activity that were excluded from the suspected attacker set because a freshly generated attacker address cannot have a prior history. That type of filtering is central to on-chain analysis. Investigators often build confidence by separating addresses that fit the attack pattern from those that do not, rather than treating every related movement as part of the same cluster.
Some chart watchers and on-chain analysts view the latest approach as more careful than earlier waves. The use of unused addresses can reduce obvious clustering, while RBF signaling may reflect an attempt to manage confirmation strategy. However, RBF also leaves a temporary opening for victims who are watching the mempool and can act quickly enough.
What Affected Users Can Do Now
Users who believe they may have generated a Coldcard seed with the affected firmware should treat the situation as urgent. The key question is whether funds are controlled by a seed created under the flawed conditions. If so, the safer course is to move funds to a new wallet address generated from a fresh seed using secure, updated firmware or another trusted setup.
Users should also check whether any outgoing transactions from their addresses are pending in the mempool. If a suspicious transaction is visible and unconfirmed, an RBF response may still be possible. That response generally requires spending the same coins to a secure address with a higher fee than the pending sweep. The practical difficulty is that the replacement must be valid and competitive before the attacker’s transaction confirms.
Because mistakes during emergency wallet moves can also lead to losses, users with large balances may seek assistance from technically competent custody professionals. The priority is to avoid entering seed phrases into untrusted websites, chat tools, unknown software, or online forms. A compromised seed should never be typed into a device or service that is not part of a carefully verified recovery process.
Custody Lessons for Bitcoin Holders
The incident highlights that hardware-wallet security depends on more than keeping a device offline. Seed creation, firmware integrity, entropy sources, backups, transaction review, and recovery planning all matter. A cold wallet can sharply reduce exposure to malware and exchange failures, but it cannot protect funds if the seed itself was generated in a predictable way.
For bitcoin holders, the clearest lesson is to track firmware advisories from wallet manufacturers and act quickly when seed-generation vulnerabilities are disclosed. It is also important to understand the difference between updating a device and migrating funds. If a seed may be compromised, the funds must move to a new seed; updating the old device does not change the private keys already derived from that seed.
FXCOINZ will continue to monitor market-level developments around the suspected sweeps, particularly whether the possible fourth wave is confirmed by further on-chain evidence and whether additional funds move from addresses tied to the same vulnerable seed-generation pattern.
Frequently Asked Questions (FAQs)
What happened to the Coldcard-generated bitcoin addresses?
A series of sweeps has targeted bitcoin held in addresses generated by Coldcard wallets. Market researchers estimate that a possible fourth wave may have brought observed movement to about 1,816 bitcoin, or roughly $114 million, from more than 5,200 addresses since July 30.
Why is the latest wave different from the earlier ones?
The latest pending transactions appear to use replace-by-fee. That means a victim who sees their address in the mempool may be able to broadcast a replacement transaction with a higher fee and move the funds first before the attacker’s transaction confirms.
What is replace-by-fee in Bitcoin?
Replace-by-fee is a Bitcoin feature that lets an unconfirmed transaction be replaced by another transaction paying a higher fee. It is usually used to speed up delayed payments, but in this case it may give affected users a narrow chance to outbid a pending sweep.
How large were the earlier sweep waves?
The first wave on July 30 took 1,083 bitcoin from 1,196 addresses in 41 minutes. Two further weekend waves brought observed losses to 1,367 bitcoin across 4,585 addresses before the possible fourth wave.
What caused the suspected vulnerability?
The suspected flaw traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer rather than the chip’s hardware randomizer. That may have made affected keys reproducible offline by someone able to identify the relevant range.
Are multisignature wallets affected?
The observed pattern suggests the issue affects single-key Coldcard seeds, and none of the first three waves touched multisignature setups. Multisignature wallets require more than one key to spend funds, which may help reduce exposure to a single compromised seed.
What should users with affected seeds do?
Users who generated a seed on the flawed software should move funds to a wallet address created with a fresh seed. Coinkite released emergency firmware for affected models, but funds controlled by a potentially compromised seed still need to be migrated.
Can a confirmed bitcoin sweep be reversed?
No. Once a Bitcoin transaction confirms, it cannot be reversed by the wallet maker, miners, exchanges, or the network. The only possible defensive window exists while a suspicious transaction remains unconfirmed in the mempool.
Photo by Bastian Riccardi on Pexels
