A fourth wave of attacks targeting Bitcoin addresses generated by the Coldcard wallet has pushed the total stolen amount close to $114 million, as reported by CoinDesk on August 3. The ongoing sweep, which began early Monday, uses bitcoin’s replace-by-fee (RBF) feature, giving victims a slim chance to recover their funds before transactions confirm.
Scope and Mechanism of the Fourth Sweep
According to Galaxy Research’s Alex Thorn, the attacker has now drained around 1,816 BTC from over 5,200 addresses since July 30. This expands on earlier incidents detailed in BTC-Pulse’s coverage of the previous wave, which affected 4,500 addresses. Unlike prior sweeps, the stolen funds are being sent to previously unused addresses, making on-chain tracing more difficult.
Replace-by-Fee Offers a Rare Window for Recovery
The use of replace-by-fee means unconfirmed transactions can be outbid by a higher fee. This is a crucial difference from earlier attacks and echoes the urgency communicated by Coinkite’s CEO, who previously urged users to move funds immediately amid the security alert. Victims who spot their addresses in the mempool have only minutes to broadcast a competing transaction with a higher fee, potentially saving their Bitcoin.
The flaw appears limited to single-key Coldcard seeds, not multisignature setups, reminiscent of the firmware bug that drained 594 BTC in 25 minutes last year, though this attack vector seems to exploit a different vulnerability. Researchers recommend that all Coldcard users monitor the mempool for their addresses and consider migrating funds to a secure wallet as soon as possible.