I used Nitter to look at X this morning, and it looked like Coinkite was destroying all their unsold Coldcard hardware wallets for new packaged ones with the updated firmware. The serialized bags they’re put in are part of their safety feature that nobody intercepted and tampered with them in shipping, so was it more cost effective to destroy them than update firmware and repackage? I’m not sure who would dare to buy any of those given the reports of late, destroying all confidence in their product’s security and even questioning their character with it possibly being a purposeful. Their only hope would be to employ a highly reputable auditing firm to thoroughly go through the device hardware engineering and the firmware code, publishing the results after any fixes suggested are implemented. And the multisig would be difficult to attack as you don’t know what keys were used with each other, but they’ll probably start testing combos when the easier coins are depleted.
The pending transactions signal replace-by-fee, so anyone who spots their address in the mempool has minutes to pay a higher fee and move funds first.
By Shaurya Malwa, Edited by Sheldon Reback

Summary
- A fourth wave of sweeps targeting bitcoin in Coldcard-generated addresses is underway, with researchers estimating the attacker has moved about 1,816 bitcoin, or roughly $114 million, from more than 5,200 addresses since July 30.
A fourth wave of sweeps against bitcoin BTC$63,775.02 addresses generated by the Coldcard cold wallet began early Monday and was still running hours later. This time, however, researchers say the transactions can be overridden while they sit unconfirmed.
Alex Thorn, head of firmwide research at Galaxy Research, flagged the active wave and said the attackers opted into replace-by-fee, a Bitcoin feature that lets a pending transaction be overwritten by a later one paying a higher fee. Until a transaction confirms, a victim who finds their address in the mempool — the queue of unconfirmed transactions — can pay more and move the coins out first.
The attack started July 30 in a sweep that took 1,083 bitcoin from 1,196 addresses in 41 minutes. Two further waves over the weekend brought observed losses to 1,367 bitcoin across 4,585 addresses.
The flaw allowing the exploit traces to a March 2021 firmware build that routed seed generation to a predictable software randomizer instead of the chip’s hardware one, leaving the resulting keys reproducible offline by anyone who works out the range. Coldcard manufacturer Coinkite released emergency firmware for every affected model and told users who had generated a seed on the flawed software to move funds to a wallet address made with a fresh one.
Thorn said he had no direct victim report and published his findings on pattern matching alone, choosing speed over confirmation to warn people while the transactions were still unconfirmed.
If it holds, however, the running total across four waves had reached about 1,816 bitcoin, near $114 million, from more than 5,200 addresses since July 30.

Thorn advised users to check funds, move anything off an affected device and bid the fee up.
The pattern covered blocks 960,778 to 960,792, with 218 transactions hitting 462 victim addresses at a rate of about 14 sweeps per block against 0.3 in a pre-incident control window, roughly 45 times normal.
Each of the spent coins that arrived after the Coldcard firmware boundary, and the destinations were fresh addresses with no prior history, one per victim rather than the shared collectors that made the first two waves easy to map.
None of the first three waves touched multisignature setups, which is consistent with the flaw affecting single-key seeds. Six destination addresses with years of prior activity also came out, since a freshly generated attacker address cannot have a history.