A fourth suspected attack wave targeting Coldcard hardware wallets has compromised 448 Bitcoin worth approximately $20 million, according to Galaxy Digital research head Alex Thorn. The series of incidents represents an escalating threat to users of the popular cold storage device.
Thorn flagged that unconfirmed transactions create a brief window for affected users to move their funds before attackers finalize the theft. This timing advantage matters because blockchain confirmations lock transactions into irreversibility. Users who detect unauthorized activity quickly enough can race to consolidate their holdings to new addresses.
The Coldcard attacks appear coordinated and systematic. Earlier waves hit the hardware wallet ecosystem with increasing sophistication, targeting devices across multiple user cohorts. The 448 Bitcoin figure marks the largest single wave documented so far, suggesting attackers have refined their methods or expanded their target list considerably.
Hardware wallet vulnerabilities typically fall into two categories. Supply chain compromise could inject malware or backdoors during manufacturing or distribution. Alternatively, attackers may exploit firmware flaws or social engineering tactics to extract private keys. The Coldcard attacks likely involve firmware manipulation or zero-day exploits that compromise the device's security model.
The incident underscores a hard reality about hardware wallets. Devices claiming "air-gapped" security still face risks from compromised firmware updates, malicious seed restoration processes, or supply chain manipulation. Users purchasing Coldcards from unofficial channels face heightened exposure.
Coldcard manufacturer Coinkite has not publicly disclosed comprehensive details about the attack vector or issued an emergency firmware patch at the time of reporting. The silence creates uncertainty about whether the vulnerability remains active or has been addressed. Users holding Coldcard devices face pressure to verify device integrity without clear manufacturer guidance.
Galaxy's warning carries weight given institutional crypto asset management context. Thorn's recommendation to monitor unconfirmed transactions reflects the reality that blockchain provides
