For five years, a ticking clock was embedded inside one of the most trusted names in Bitcoin self-custody. Now, with more than 1,800 Bitcoin — worth approximately $114 million — drained since last Thursday alone, that clock has stopped, and the damage it leaves behind is staggering. A fourth wave of coordinated attacks targeting Coldcard hardware wallets confirmed over the weekend that this is not a contained incident but an ongoing, systematic exploitation of a vulnerability that should never have survived to 2026.
The root cause traces back to a firmware update that Coldcard shipped in 2021. That release contained a bug that rendered wallet seed generation guessable under certain conditions — meaning that an attacker with sufficient computational resources and knowledge of the flaw could reconstruct the private keys of affected devices without ever physically touching the hardware. The promise of a hardware wallet is air-gap security: your keys never leave the device, and brute force is rendered economically irrational. When seed generation itself is broken, that promise collapses entirely. The attacker does not need to steal your device. They only need to know your device is vulnerable.
Four Waves, One Root Cause
The pattern of four distinct attack waves is telling. This is not opportunistic theft. Someone — or some group — identified the vulnerable firmware versions, built tooling to reconstruct affected seeds at scale, and has been methodically working through a target list. Each wave suggests a deliberate operational cadence: probe, drain, withdraw, pause, repeat. The fact that a fourth wave is still executing as of this writing means the attackers have not exhausted their list of compromised addresses. The pool of vulnerable wallets created under that 2021 firmware may still be larger than what has been emptied so far.
The 1,800 BTC figure represents what has moved since Thursday. It does not necessarily represent the total stolen across all four waves combined. If earlier waves preceded this week's haul, the cumulative losses could be significantly higher — though the source material centers on the current attack window as the primary measure. What is clear is that the pace has accelerated. A fourth wave arriving this quickly after prior sweeps suggests attackers are racing against the clock, aware that public disclosure may drive remaining victims to move their funds before the attackers can.
The Mempool Window: A Narrow Lifeline
There is one piece of genuinely actionable intelligence buried inside this crisis. The latest batch of drain transactions has not yet fully cleared the Bitcoin mempool. Because Bitcoin transactions compete for block space by fee rate, a victim whose funds are currently in an attacker-initiated outbound transaction can, under specific conditions, attempt to replace or outbid that transaction using Replace-By-Fee (RBF) mechanisms — effectively redirecting the coins to a safe address before miners confirm the attacker's version.
This is not a guaranteed rescue. It requires technical competence, immediate action, and a degree of luck around block timing and mempool congestion. But it is a window that exists right now and will close permanently once the relevant transactions receive sufficient confirmations. Any Coldcard user who set up their wallet using firmware from 2021 or who has not verified their firmware provenance should treat this as an emergency. Move your coins to a freshly generated wallet on unaffected hardware, and do it before the mempool clears.
Hardware Wallets and the Liability of Trust
The deeper issue this crisis surfaces is structural. Hardware wallets occupy a peculiar position in the security stack: they are marketed as the endpoint of trust, the final physical barrier between an attacker and a user's funds. When that barrier is compromised not by a physical attack but by a software defect in the device's own firmware, users have almost no recourse. They followed best practices. They bought dedicated hardware. They kept their seed phrases offline. And they were still drained.
Coldcard has historically enjoyed a strong reputation among technically sophisticated Bitcoin holders precisely because of its emphasis on open-source firmware and security-first design. A firmware bug that went undetected — or unpatched — for five years is a significant credibility event for the product and for the hardware wallet category broadly. The question of when the vulnerability was discovered, when it was disclosed internally, and what notification obligations existed for affected users will be central to any post-mortem accountability.
What This Means for Self-Custody
The $114 million threshold is a psychological marker, but the real damage is to the model of trustless self-custody itself. Every time a flagship security product fails at this scale, it pushes users toward custodial solutions — exchanges, institutional vaults, managed wallets — which carry their own distinct risk profiles. The answer is not to abandon hardware wallets or self-custody. The answer is to demand reproducible firmware builds, mandatory security audits with public disclosure timelines, and clear vulnerability response protocols from every hardware manufacturer in this space.
If you hold Bitcoin on a Coldcard device initialized under firmware from 2021, the time to act is now. Check your firmware version, verify your seed against known affected ranges if tooling becomes available, and assume the worst until you can confirm otherwise. The mempool window will not stay open long.
Written by the editorial team — independent journalism powered by Bitcoin News.