Crypto

Coldcard Wallet Flaw Triggers Fourth Sweep Near $114 Million Loss

724FinanceCem Talu
Key Highlights

Coldcard soğuk cüzdan kullanıcıları, yeni bir saldırı dalgasının **1,816 BTC** (~**$114 milyon**) kaybına yol açabileceği uyarısını aldı. ## Dördüncü

Coldcard Wallet Flaw Triggers Fourth Sweep Near $114 Million Loss

Coldcard cold‑wallet users have been warned that a new attack wave could siphon 1,816 BTC (~$114 million) from vulnerable addresses.

Fourth Sweep: Rapid RBF‑Driven Heists

Attackers are exploiting Bitcoin's replace‑by‑fee (RBF) mechanism to overwrite unconfirmed transactions. By posting a higher‑fee transaction to the mempool, they can supersede the victim's pending transfer and seize the funds.

Wave‑by‑Wave Breakdown

  • 1,083 BTC stolen in the first wave over 41 minutes from 1,196 addresses.
  • Two weekend waves added 1,367 BTC across 4,585 addresses.
  • The fourth wave pushed the total to 1,816 BTC from over 5,200 addresses, nearing $114 million.
  • Sweep frequency spiked to about 14 per block – roughly 45× the baseline rate.
  • Technical Roots: RBF Abuse & Firmware Bug

    Researchers traced the exploit to a March 2021 firmware build that routed seed generation to a predictable software RNG instead of the chip's hardware RNG, making private keys reproducible offline.

    Coinkite’s Emergency Response

    Coldcard maker Coinkite rolled out emergency firmware for all affected models and urged users who generated seeds on the flawed software to move funds to a fresh address. The flaw impacts single‑key seeds; multisig setups remained untouched.

    Market & Investor Implications

  • Binance maintains its market‑leader status, but security breaches like this can spike volatility in spot and derivatives markets.
  • Institutional investors will likely reassess cold‑wallet security protocols and demand stricter audit trails.
  • The misuse of RBF may reignite protocol‑governance debates within the Bitcoin community.
  • The Coldcard incident underscores that even hardware wallets cannot be fully insulated from software vulnerabilities. RBF, when combined with a flawed RNG, creates a potent attack vector. Users must vigilantly monitor firmware updates and practice disciplined seed hygiene to avoid irreversible losses. Transitioning to multisig solutions can further mitigate single‑key exposure, signaling a shift toward more robust crypto‑asset governance and risk‑management frameworks.

    Related News & Analysis

    View All →

    Latest Market News

    All News →
    C

    Financial Analyst: Cem Talu

    Software-oriented blockchain researcher and crypto investor. Innovative, technology-focused.

    Disclaimer: The investment information, comments, and recommendations contained herein are not within the scope of investment advisory. Investment advisory services are provided individually by authorized institutions, taking into account the risk and return preferences of individuals. The comments and recommendations contained herein are general in nature. These recommendations may not be suitable for your financial situation and your risk and return preferences. Therefore, making an investment decision based solely on the information contained herein may not produce results that meet your expectations.

    © 2026 724Finance - All Rights Reserved.Original Source: CoinDesk