Bitcoin cold-wallet losses may near $114 million as possible fourth sweep emerges
The pending transactions signal replace-by-fee, so anyone who spots their address in the mempool has minutes to pay a higher fee and move funds first.
By Shaurya Malwa|Edited by Sheldon Reback
Updated Aug 3, 2026, 9:09 a.m. Published Aug 3, 2026, 8:51 a.m.
Share this article

Summary
A fourth wave of sweeps against bitcoin BTC$62,561.89 addresses generated by the Coldcard cold wallet began early Monday and was still running hours later. This time, however, researchers say the transactions can be overridden while they sit unconfirmed.
Alex Thorn, head of firmwide research at Galaxy Research, flagged the active wave and said the attackers opted into replace-by-fee, a Bitcoin feature that lets a pending transaction be overwritten by a later one paying a higher fee. Until a transaction confirms, a victim who finds their address in the mempool — the queue of unconfirmed transactions — can pay more and move the coins out first.
The attack started July 30 in a sweep that took 1,083 bitcoin from 1,196 addresses in 41 minutes. Two further waves over the weekend brought observed losses to 1,367 bitcoin across 4,585 addresses.
The flaw allowing the exploit traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the chip’s hardware one, leaving the resulting keys reproducible offline by anyone who works out the range. Coldcard manufacturer Coinkite released emergency firmware for every affected model and told users who had generated a seed on the flawed software to move funds to a wallet address made with a fresh one.
Thorn said he had no direct victim report and published his findings on pattern matching alone, choosing speed over confirmation to warn people while the transactions were still unconfirmed.
If it holds, however, the running total across four waves had reached about 1,816 bitcoin, near $114 million, from more than 5,200 addresses since July 30.

Thorn advised users to check funds, move anything off an affected device and bid the fee up.
The pattern covered blocks 960,778 to 960,792, with 218 transactions hitting 462 victim addresses at a rate of about 14 sweeps per block against 0.3 in a pre-incident control window, roughly 45 times normal.
Each of the spent coins that arrived after the Coldcard firmware boundary, and the destinations were fresh addresses with no prior history, one per victim rather than the shared collectors that made the first two waves easy to map.
None of the first three waves touched multisignature setups, which is consistent with the flaw affecting single-key seeds. Six destination addresses with years of prior activity also came out, since a freshly generated attacker address cannot have a history.
Related Assets
- 1
- 2
- 3
- 4
- 5
- 6
Counting down the days: State of Crypto
15 hours ago
- 7
- 8
- 9
- 10
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
Jun 29, 2026
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.
Why it matters:
Binance remains crypto’s leading exchange, expanding from spot and derivatives into RWAs, payments, savings, yield, and broader financial services.


