Users of the Coldcard hardware wallet, designed for securely storing Bitcoin, are encountering a significant surge in thefts following a recent series of coordinated attacks. These breaches have targeted several hundred addresses, alarming the cryptocurrency community.
What Are the Latest Figures?
Alex Thorn, who leads research at Galaxy, disclosed that attackers during the latest incident focused on 462 potential victims. The operations resulted in 218 transactions, moving 388.9 Bitcoin in total. Comparatively, the average sweeps per block surged to 13.8, drastically higher than the previous stability observed before these attacks.
How Are the Assets Being Moved?
The stolen Bitcoin is typically transferred to new wallets instead of pooling into a single repository, complicating tracking efforts. Some of these assets have already been redirected to secondary wallets, commonly known as “second hop” addresses, making tracing exceedingly difficult.
Many of these transactions are still awaiting confirmation on the blockchain, with suspicious activity visible in the Bitcoin network’s mempool of unconfirmed transactions. The distinct characteristics of these attacks strongly link them to Coldcard wallets due to their technical traces and frequency patterns.
The table below showcases key metrics from this latest wave:
- 462 addresses affected.
- 218 transactions recorded.
- 388.9 BTC moved.
- Sweeps per block spiked to 13.8 from approximately 0.3.
Thorn advised that users whose transactions aren’t yet confirmed may act quickly to secure their funds by broadcasting a higher-fee transaction to transfer their Bitcoin to a safer wallet. This proactive step can potentially thwart ongoing theft attempts.
“These are likely Coldcard victims — they match the shape of Coldcard vulnerable UTXOs and the elevated transaction pattern gives me high confidence they are another wave of attacks,” Thorn stated.
Security experts continue to caution Coldcard users, emphasizing the heightened risk for those who have not yet secured their holdings in more protected configurations. Current estimates suggest that losses tied to these vulnerabilities could reach approximately $70 million.



