A suspected fourth wave of coordinated attacks targeting Coldcard hardware wallets has swept 389 Bitcoin from victims, according to a warning issued by Galaxy Research head Alex Thorn — marking what may be one of the most consequential ongoing hardware wallet security crises in recent memory. Thorn added a critical caveat for affected users: because some transactions remain unconfirmed on the Bitcoin network, a narrow window may still exist for certain Coldcard holders to intervene and recover their funds before they are permanently lost.
The sheer scale of the alleged theft demands attention. At prevailing Bitcoin valuations, 389 Bitcoin represents a significant sum — one that underscores not merely the technical sophistication of whoever is behind these attacks, but the systemic risk now hovering over an entire category of hardware security devices that millions of cryptocurrency holders have long considered among the safest means of cold storage. The Coldcard wallet, produced by Coinkite, has historically been regarded as one of the most security-hardened options available to self-custody Bitcoin holders.
Thorn's warning is particularly significant given his position. As research head at Galaxy, one of the most closely watched institutional voices in digital asset markets, his public alert carries the weight of institutional due diligence. The framing of this as a "suspected" fourth wave implies that prior attack incidents have already been identified, analyzed, and attributed to a common threat actor or vulnerability — even if the precise mechanism of exploitation has not yet been disclosed publicly, or is being withheld to protect ongoing investigations and user safety.
The mechanics of the attack remain under scrutiny, but the pattern of a fourth wave suggests a persistent and adaptive adversary rather than an opportunistic one-time exploit. Hardware wallet attacks of this nature can arise from a range of vectors: supply chain compromise, firmware vulnerabilities, seed phrase extraction through side-channel attacks, or social engineering targeting users into installing malicious updates. That a fourth wave has now been identified implies that prior mitigation efforts — whether by Coinkite, the broader security community, or users themselves — have not fully neutralized the threat.
The detail about unconfirmed transactions is operationally critical and deserves particular emphasis for any Coldcard user who suspects their device may be compromised. On the Bitcoin network, transactions broadcast to the mempool are not immediately irreversible. Until a transaction is confirmed within a mined block, there remains a technical possibility — through mechanisms such as Replace-by-Fee (RBF) — that a competing transaction could be broadcast to redirect funds to a safe address before the attacker's transaction settles. This is the narrow opportunity Thorn referenced, and it is one that closes quickly as blocks are mined approximately every ten minutes.
For holders who have not yet been affected, the incident reinforces a set of principles that security professionals have long advocated but that user behavior data suggests remain widely ignored: regularly verify firmware integrity through official channels only, purchase hardware wallets exclusively from manufacturers or verified distributors to reduce supply chain exposure, and maintain awareness of any unusual transaction activity. The broader lesson, one that each successive wave of these attacks hammers home with increasing financial urgency, is that hardware security is not a static guarantee — it requires active stewardship.
The timing of this suspected fourth wave also raises uncomfortable questions about the cadence of disclosure. If prior waves have already been documented and warnings issued, the recurrence suggests that either the remediation advice has not reached a sufficient proportion of the affected user base, or that the attack vector itself has not been fully closed. In either case, the responsibility for more aggressive, coordinated public disclosure falls on both the manufacturer and the broader institutional research community that, like Thorn, has visibility into on-chain activity patterns.
What This Means for Hardware Wallet Holders
The suspected fourth Coldcard attack wave — and the 389 Bitcoin already swept — is a live crisis, not an academic risk scenario. Any user holding Bitcoin on a Coldcard device should treat the situation with immediacy: monitor their wallet addresses for unauthorized activity, cross-reference transaction histories, and if an outgoing transaction appears that was not self-initiated, act within the mempool window before confirmation. Beyond the immediate response, this episode should prompt a broader reassessment of cold storage assumptions across the self-custody community. No hardware device is invulnerable indefinitely, and the adversaries exploiting Coldcard users have now demonstrated both persistence and scale. The 389 Bitcoin figure will likely grow in visibility as this story develops — and may yet grow in magnitude.
Written by the editorial team — independent journalism powered by Codego Press.