The fourth wave of the Coldcard sweep landed sometime in the last 48 hours, and it was not subtle. 47 addresses, most of them dormant since 2020 or earlier, woke up and broadcast transactions in almost identical shapes: one output, a fee rate just high enough to attract a miner, and a destination address with no previous transaction history. That is not organic whale movement. That is a machine-driven sweep. The total loss across all four waves now exceeds $114 million in Bitcoin, and the attack is still in progress. The code doesn't lie. The people selling security narratives around it often do.
I have spent the past decade reading on-chain data as a forensic document. During the 2017 ICO boom, I manually audited the Zilliqa genesis block and found an integer overflow bug in the sharding protocol that forced a two-week mainnet delay. That experience taught me a permanent habit: when a system fails, do not ask who to blame first. Ask what exactly broke, where the failure lives, and who can still move funds out of the blast radius. The Coldcard case is a textbook example of why that habit matters.
This is not a compromise of Bitcoin’s consensus layer. It is not a hack of a secure element chip. It is a firmware-level entropy failure from 2021. Certain Coldcard firmware versions generated seed phrases with insufficient randomness. Attackers identified that flaw, enumerated the seed space, derived private keys for addresses that had ever received funds, and began issuing sweeping transactions. In plain language: some hardware wallets that were supposed to hold private keys offline actually generated keys that an attacker could reconstruct from a predictable source.
The metadata holds the provenance the price ignored. Block explorers show these sweep transactions as ordinary high-value transfers. The price of Bitcoin did not react. But on-chain, the signature is unmistakable. The addresses were not newly created. They came from old cohorts. They had not interacted with each other before. Their inputs spent entire UTXO balances in a single move, which is the behavior of an attacker clearing an account, not a user consolidating funds.
Let me make the threat model explicit. A Coldcard wallet is a type of self-custody hardware solution. The private key is generated from a seed phrase, which is supposed to be produced by a random number generator inside the device. If that generator produces a limited or predictable set of outputs, then any seed generated by the affected firmware exists inside a finite search space. An attacker does not need to steal the physical device. They do not need to intercept a shipment. They merely need to compute every possible seed from the flawed RNG, derive the corresponding Bitcoin addresses, and check which ones hold a non-zero balance. This is an offline cracking game, not a network intrusion.
The fact that the attack has continued into a fourth wave tells me the enumeration is not finished. Either the vulnerable seed space is wider than first believed, or the attacker is methodically processing a large batch of derived keys. Either scenario is dangerous. And because the attacker is sweeping funds through the mempool in real time, the victim still has an active, but shrinking, window to fight back.
This is where the technical nuance matters. When an attacker broadcasts a sweep transaction from a compromised address, that transaction waits in the mempool until a miner confirms it. The original owner of that address still controls the same private key, because the seed was not stolen in the traditional sense; it was predicted. That means the victim can create a competing transaction that spends the same inputs to their own safe address. The question is whether that competing transaction can beat the attacker’s transaction into a block.
There are two methods. The first is Replace-By-Fee, or RBF. If the attacker’s transaction has opted into RBF, the victim can submit a new transaction with the same inputs, a higher fee, and new destination addresses, and the network will replace the old one. The second method is Child-Pays-For-Parent, or CPFP. If the victim cannot replace the transaction directly, they can broadcast their own sweep transaction and then attach a child transaction that pays an additional fee to incentivize miners to include the parent. In practice, miners do not like to lose fees, so a sufficiently high CPFP bump can get a competing transaction confirmed first.
But there is a brutal catch. The attacker is watching the same mempool. If they see a victim trying to rescue funds, they can raise their own fee, send another sweep, or use a transaction that is not replaceable. This is a race. The attacker has no incentive to wait. The only advantage the victim has is knowledge of the vulnerability and a quick connection to a mining pool with direct submission.
This is why I am advising every affected Coldcard user to move funds immediately, not after reading three more blog posts. The mempool window is measured in minutes, not days. If a sweep transaction has already been confirmed against your address, you are done. The funds are gone. If the transaction is still unconfirmed, contact a professional transaction accelerator, use a wallet that supports CPFP, and do not reuse any address from the compromised wallet.
Tracing the ghost liquidity behind this hardware-wallet drain shows that the sweep transactions are consolidating into a small number of high-volume addresses. Those addresses have not yet moved to a known exchange in any meaningful size. The attacker is likely waiting. Following the exit liquidity to its cold storage, I see no panic-driven OTC dump. That is a warning, not a relief. It means the attacker may be in no hurry to liquidate, which gives them more time to continue harvesting the remaining vulnerable seeds.
The lack of an official, detailed disclosure from Coinkite is also telling. The parsed reports mention a 2021 firmware bug, but they do not include which exact firmware versions, which batch of seed generation dates, or which entropy source failed. Based on my audit experience, that level of opacity makes it impossible for users to assess their own exposure. A hardware wallet vendor cannot simply say “stop using old firmware.” Users need a concrete query: was your seed generated before a specific firmware update? If the answer is yes, you must assume the seed is in the attacker’s dictionary.
In the absence of that disclosure, the safe threshold is ruthless. If your Coldcard seed predates 2022 and you cannot verify the exact RNG implementation, move your Bitcoin to a newly generated wallet with audited entropy. Do not cross-sweep from a compromised seed to a new seed on the same device. Use a different device, a different software wallet, or a fresh Coldcard with a verified secure firmware. The cost of paranoia is small compared to the cost of losing everything.
The contrarian angle here is that this attack is not an indictment of hardware wallets as a category. It is an indictment of unverifiable firmware. The market’s gut reaction will be to say “self-custody is dead” or “Coldcard users deserved it for being too technical.” That is correlation being mistaken for causation. Ledger and Trezor do not necessarily have the same entropy defect. The real lesson is broader: every hardware wallet vendor needs to open its RNG process to third-party audit, publish deterministic firmware hashes, and provide a public mechanism for testing a seed’s generation source.
The deeper systemic risk is the information asymmetry. Attackers knew about this vulnerability before the public did. They exploited it quietly, testing small balances, then scaling into a $114 million sweep. The users who were most likely to run old firmware were also the users least likely to hear about an obscure disclosure thread in time. This is not a technical failure alone. It is a failure of user communication, regulatory speed, and vendor responsibility.
The opportunity side of this story is equally clear. Emergency transaction acceleration is now a life-saving service, not just a convenience. Exchanges and mining pools that step forward to tag and delay known sweep transactions will earn trust that no marketing campaign can buy. Security teams that offer firmware entropy audits and seed-generation forensics will find a hungry market. But those same tools can be used by attackers to race faster, so the industry needs to move with the same speed as the adversary.
I am watching five signals over the next week. First, is there a fifth wave of sweeps? If yes, the vulnerable seed space is broader than the initial disclosure suggests. Second, do any mempool monitors see failed replacement attempts by victims? That would indicate the rescue window is still open for some. Third, will any mining pool publicly identify and refuse to confirm transactions from the known attacker addresses? Fourth, will Coinkite issue a clear firmware migration plan or a compensation program for affected users? Fifth, will security researchers release batch vulnerability audits for other hardware wallets? Any of these signals would change the risk assessment from a contained incident to an industry-wide event.
The most important thing is not to let the price chart distract you. Bitcoin’s fundamentals are not driving this story. The macro liquidity cycle is still the dominant factor for the next few months. But the trust erosion in self-custody is a slower, quieter force. Every user who hesitates to move funds because they do not know whether their seed is vulnerable is another potential victim.
I tell everyone the same thing: verify, don’t trust, and when in doubt, move the coins. The block confirms all. But the mempool is where wars are won and lost. If you have even a remote connection to a Coldcard from the 2021 era, you are not being paranoid. You are being rational. The code doesn’t lie, and it has already shown you the inventory of damages.
The attack is ongoing. The window is closing. The only question is whether the industry learns this lesson before the next hardware vendor repeats it.

