For fifteen years, Bitcoin’s core promise sold itself in five words: not your keys, not your coins. Hold your own hardware wallet, and no exchange collapse, no bank freeze, and no government seizure could touch you. That pitch has been bleeding out for four days straight now, and Monday brought a fourth wound.
A new wave of sweeps against Coldcard-generated wallets began early Monday and was still running hours later, according to Galaxy Research. Combined with three earlier waves dating back to 30 July, the running total has climbed to roughly 1,816 BTC, close to $114 million, drained from more than 5,200 addresses. Every previous estimate has already been overtaken by the next one. This is the fourth in five days.
The mechanics haven’t changed since the first sweep. A March 2021 firmware build on certain Coldcard devices, made by Canadian manufacturer Coinkite, generated wallet seeds using a predictable software fallback instead of the device’s proper hardware random number generator. Keys that owners believed were cryptographically unguessable turned out to be reconstructable offline by anyone willing to work through the possibilities. No phishing, no malware, no victim error. Just years of dormant coins sitting in wallets broken from the moment they were created.
Unlike the first three waves, this batch of transactions is using Bitcoin’s replace-by-fee feature, which lets a pending transaction be overwritten by a later one that pays a higher fee. Until a transaction actually confirms on the blockchain, anyone who spots their own address sitting in the mempool, the queue of unconfirmed transactions, has a window measured in minutes to outbid the attacker and move their coins first.

Alex Thorn, Galaxy’s head of firmwide research, flagged the active wave and has been tracking the pattern in near real time. He has been candid that this latest assessment is based on judgment rather than confirmation. He said he has no direct victim report for wave four and published the finding on pattern matching alone, choosing to warn people while the transactions were still unconfirmed rather than wait for certainty. That’s to say that this is Thorn’s read of on-chain behaviour, not a confirmed theft report, and it should be weighed as such even as the earlier three waves have already been independently corroborated.
The numbers behind wave four are stark. Blocks 960,778 to 960,792 saw roughly 14 sweeps per block against a pre-incident baseline of about 0.3, some 45 times normal activity. Two hundred and eighteen transactions hit 462 victim addresses. Unlike the earlier waves, funds are being routed to fresh, previously unused addresses rather than the shared collector wallets that made the first two sweeps relatively easy to trace, a shift that suggests whoever is running this has adapted to the scrutiny.
Meanwhile, none of the four waves has affected multisignature setups, which corroborates Coinkite’s account that the flaw lies specifically in single-key seed generation. Six destination addresses with years of prior transaction history were also excluded from the pattern on the logic that a genuinely fresh attacker address cannot have an existing history.
Coldcard’s heist proves there’s no safe haven
Here is what four straight days of sweeps have actually proven: the industry’s founding sales pitch was never fully true, and it took a market leader quietly poisoning thousands of wallets for five years before anyone noticed. The average stolen coin, across the confirmed waves, had sat untouched for 3.18 years. These weren’t day traders caught napping. These were the model citizens of self-custody, doing exactly what the evangelists told them to do: buy reputable hardware, generate the seed offline, never touch the internet, wait.
Canadian coach Jonathan Goodman lost 18.25 BTC in a seven-minute window despite keeping his keys in a bank safety deposit box that never touched a network cable. “Perhaps the hardest part about this is that I did everything right,” he said. He’s correct, and that’s precisely the problem: the failure wasn’t in his discipline; it was baked into the device before he ever bought it.
Coinkite CEO Rodolfo Novak has apologised publicly and pushed emergency patches, while still noting the company hasn’t confirmed the firmware bug caused any specific reported theft. A patch cannot repair a seed that already exists. Coinkite’s own guidance points to 50 independent dice rolls for entropy, a BIP-39 passphrase, or multisig as the only precautions that actually would have held, protections that were buried in documentation rather than pushed to customers as a requirement. Nobody told ordinary holders they needed insurance against their own hardware manufacturer.

Then came Changpeng Zhao, founder of the exchange that self-custody was invented to make obsolete, telling holders that “nothing is 100% safe” and urging them to spread funds across multiple wallets.
It’s sound advice, although it might appear self-serving. CZ has spent years fielding the same line thrown back at him: that centralised exchanges are the thing you’re supposed to escape, and a hardware wallet catastrophe of this size is the first real opening he’s had to reframe the argument as “everything is risky, so why not trust us instead.” That doesn’t make him wrong about the physics of risk. It does mean his framing deserves the same scepticism crypto has learned to apply to every other founder with a stake in the answer.
CryptoQuant data shows a reversal of the pattern seen after FTX’s collapse: instead of fleeing exchanges for self-custody, smaller holders are moving Bitcoin back onto platforms like Binance, Kraken and OKX, chasing safety in the very custodians self-custody was built to replace. Five years ago, that flow ran the other way. That reversal, more than any single stolen coin, is the real headline: the industry spent a decade telling people to trust cold wallets over exchanges, and one incident was enough to send them running back to the middlemen.
As the numbers continue to stack up, the practical advice remains: check whether your Coldcard seed predates the fix, move assets to a wallet generated on current firmware, and if you see your own address sitting unconfirmed in the mempool right now, don’t wait to bid the fee up.