3 hours ago

Coldcard Bitcoin Sweeps May Near $114M as Fourth Wave Emerges

Coldcard wallet losses may near $114 million as possible fourth sweep emerges

CoinDesk

Key Point

A fourth wave of sweeps against bitcoin addresses generated by the Coldcard cold wallet began early Monday and was still running hours later. Researchers estimate the attacker has moved about 1,816 BTC, or roughly $114 million, from more than 5,200 addresses since July 30. Galaxy Research's Alex Thorn said attackers opted into replace-by-fee, which lets a pending Bitcoin transaction be overwritten by a higher-fee transaction. Thorn said victims who find their address in the mempool can pay more and move coins out before confirmation. The pattern suggests the flaw affects single-key Coldcard seeds and not multisignature setups.

Why it matters: A large active wallet sweep could weaken confidence in single-key self-custody if affected users cannot move funds before confirmation.

Market Sentiment

Bearish, Stress-on, Event-driven, De-risking.

Reason: A possible Coldcard address sweep has moved about 1,816 bitcoin, which points to direct self-custody risk.

Similar Past Cases

In June 2023, Atomic Wallet users reported more than $35 million in stolen crypto after a broad wallet compromise, and the event pressured trust in non-custodial wallet security. (Fortune) Difference: Atomic Wallet involved a hot wallet and multiple crypto assets, while the current case centers on Coldcard-generated bitcoin addresses and an active replace-by-fee window.

Ripple Effect

A wallet-generation flaw can push holders from self-custody into emergency key rotation and reduce trust in single-key storage. If more unconfirmed sweeps appear, then mempool monitoring and fee-bumping success would show whether losses are still preventable. If confirmed losses keep rising after this wave, then hardware-wallet trust could weaken beyond the affected addresses.

Opportunities & Risks

Opportunities: If victims identify unconfirmed sweeps in the mempool, then higher-fee replacement transactions are a potential loss-reduction signal for affected holders. If evidence continues to point away from multisignature setups, then migration toward multisignature after funds are secured can reduce single-key exposure.

Risks: If sweeps confirm before victims can override them, then reducing exposure to affected single-key addresses limits further loss risk. If attackers keep sending funds to previously unused addresses, then tracing and recovery may become harder.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.