A hardware wallet security crisis is deepening. What began as a discrete cryptographic flaw inside Coldcard Bitcoin wallets has now expanded into what researchers describe as a fourth coordinated attack wave, with 462 new suspected victims identified — adding to an already staggering toll of compromised funds and addresses that has shaken confidence in cold-storage security fundamentals.

Galaxy Research head Alex Thorn issued a stark warning early Monday, alerting the Bitcoin community that a fourth wave of attacks is likely underway against users of the Coldcard hardware wallet. Thorn's warning follows three already confirmed attack waves in which the random number generator (RNG) exploit has been linked to the theft of 1,367.05 BTC across 4,585 separate wallet addresses. If the suspected fourth wave is verified, both totals will climb materially higher.

The Anatomy of an RNG Failure

At the heart of this crisis lies a flaw in the random number generator — the cryptographic component responsible for producing the private keys that protect a wallet's funds. A compromised or predictable RNG does not simply weaken security at the margins; it can render private key generation entirely reproducible by a sophisticated attacker. In practice, this means an adversary who understands the flaw can reconstruct the private keys of affected wallets and drain their funds at will, without ever physically possessing the device. The attack model is particularly insidious because victims may see no visible sign of compromise until their balances disappear.

Hardware wallets have long been marketed — correctly, under normal circumstances — as the gold standard of self-custody security. They keep private keys air-gapped from internet-connected environments, protecting users from remote attacks that routinely devastate software wallets and exchange accounts. An RNG vulnerability of this nature strikes at the single most critical assumption underpinning that security guarantee: that the keys themselves were generated securely in the first place. If that assumption fails, the air-gap provides no meaningful protection.

Scale and Coordination Signal Sophisticated Threat Actor

The structured, wave-based pattern of the attacks is itself significant. Three confirmed waves of exploitation across 4,585 addresses, with a suspected fourth wave now adding approximately 462 new suspected victims, suggests a deliberate and methodical campaign rather than opportunistic theft. A threat actor operating in coordinated waves may be systematically working through a database of vulnerable addresses — possibly derived from their own prior knowledge of the RNG flaw — draining wallets in batches to manage on-chain footprint and complicate blockchain forensics.

The total of 1,367.05 BTC linked to the first three confirmed waves represents substantial real-world value. At prevailing Bitcoin prices, that figure translates to tens of millions of dollars in losses for individual holders who placed trust in hardware-based self-custody. The psychological damage to the broader cold-storage ecosystem may be equally consequential: retail and institutional holders alike are now confronting the uncomfortable reality that hardware wallet security is not unconditional.

Implications for Self-Custody and the Broader Market

The Coldcard incident arrives at a moment when self-custody has been experiencing renewed advocacy across the Bitcoin community, driven in part by lingering institutional distrust following high-profile exchange collapses in recent years. The argument for self-custody rests entirely on the integrity of the key generation process — and a systemic RNG flaw of this scale fundamentally undermines that argument for the affected device population.

Regulators and compliance professionals monitoring the digital assets space will also take note. An exploit of this size and structure generates precisely the kind of illicit fund flows that trigger scrutiny under anti-money laundering (AML) frameworks. Blockchain analytics firms are likely already tracking the movement of the 1,367.05 BTC across the affected 4,585 addresses, and any identified consolidation wallets could become targets for asset freezing if they interact with regulated on-ramps.

What This Means for Coldcard Users

For current Coldcard holders, the priority question is whether their device or firmware version falls within the scope of the compromised RNG. Users should monitor communications from Coinkite, the manufacturer behind Coldcard, and cross-reference any firmware advisories against the device versions implicated in the four waves. Critically, simply moving funds to a new address on a potentially compromised device does not resolve the exposure — if the RNG is flawed, any new key generated on the same device inherits the same vulnerability. Affected users should generate replacement wallets on a device with a verified, uncompromised RNG before transferring funds.

Alex Thorn's early Monday warning underscores the speed at which on-chain researchers are tracking this campaign. The fact that a fourth wave of 462 suspected victims was identified and flagged publicly before formal confirmation speaks to the maturity of blockchain forensics infrastructure — but also to the urgency of the threat. The community now awaits confirmation of whether the fourth wave crosses the threshold into verified status, and whether the attacker's database of vulnerable addresses is yet exhausted.

Written by the editorial team — independent journalism powered by Codego Press.