Coldcard Bitcoin Sweep Moves $114M as Fourth Wave Emerges

iconNS3
Share
AI summary iconSummary
Bitcoin breaking news: A fourth wave of Bitcoin sweeps targeting Coldcard-generated addresses began early Monday, still active hours later. Researchers track 1,816 BTC, or $114 million, moved from over 5,200 addresses since July 30. Galaxy Research's Alex Thorn said attackers used replace-by-fee to overwrite pending transactions. Funds may still be reclaimable with higher fees. The flaw mainly affects single-key Coldcard seeds, not multisignature setups. Active wallet sweeps could shake user confidence in single-key custody if funds are locked before confirmation.

Key Point

A fourth wave of sweeps against bitcoin addresses generated by the Coldcard cold wallet began early Monday and was still running hours later. Researchers estimate the attacker has moved about 1,816 BTC, or roughly $114 million, from more than 5,200 addresses since July 30. Galaxy Research's Alex Thorn said attackers opted into replace-by-fee, which lets a pending Bitcoin transaction be overwritten by a higher-fee transaction. Thorn said victims who find their address in the mempool can pay more and move coins out before confirmation. The pattern suggests the flaw affects single-key Coldcard seeds and not multisignature setups.

Why it matters: A large active wallet sweep could weaken confidence in single-key self-custody if affected users cannot move funds before confirmation.

Market Sentiment

Bearish, Stress-on, Event-driven, De-risking.

Reason: A possible Coldcard address sweep has moved about 1,816 bitcoin, which points to direct self-custody risk.

Similar Past Cases

In June 2023, Atomic Wallet users reported more than $35 million in stolen crypto after a broad wallet compromise, and the event pressured trust in non-custodial wallet security. (Fortune) Difference: Atomic Wallet involved a hot wallet and multiple crypto assets, while the current case centers on Coldcard-generated bitcoin addresses and an active replace-by-fee window.

Ripple Effect

A wallet-generation flaw can push holders from self-custody into emergency key rotation and reduce trust in single-key storage. If more unconfirmed sweeps appear, then mempool monitoring and fee-bumping success would show whether losses are still preventable. If confirmed losses keep rising after this wave, then hardware-wallet trust could weaken beyond the affected addresses.

Opportunities & Risks

Opportunities: If victims identify unconfirmed sweeps in the mempool, then higher-fee replacement transactions are a potential loss-reduction signal for affected holders. If evidence continues to point away from multisignature setups, then migration toward multisignature after funds are secured can reduce single-key exposure.

Risks: If sweeps confirm before victims can override them, then reducing exposure to affected single-key addresses limits further loss risk. If attackers keep sending funds to previously unused addresses, then tracing and recovery may become harder.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.