A suspected fourth coordinated attack wave targeting Coldcard hardware wallets has stripped 389 Bitcoin from affected users, according to a warning issued by Alex Thorn, head of research at Galaxy. The alarm comes with a razor-thin silver lining: Thorn noted that some transactions had not yet been confirmed on-chain at the time of his warning, meaning a subset of victims may still have a brief window to intercept the movement of their funds before they are permanently lost.

The figure of 389 Bitcoin is not abstract. At current valuations, that represents a multi-million dollar loss concentrated among users of a device that has long been marketed on its security credentials. Coldcard, manufactured by Coinkite, has been a preferred custody tool among technically sophisticated Bitcoin holders — precisely the demographic that tends to hold larger balances and treat self-custody as a philosophical commitment, not merely a convenience. The irony of a hardware wallet becoming a vector for loss at this scale is not lost on the community.

A Pattern, Not an Incident

The designation of this event as a "fourth wave" is the detail that demands the most scrutiny. Single incidents can be attributed to user error, phishing, or isolated firmware exploits. Four sequential waves suggest something more systemic — either a persistent vulnerability in the device or its supply chain, a compromised seed generation process, or a sophisticated actor with sustained access to information about Coldcard users and their configurations. None of those possibilities is reassuring, and none has been publicly confirmed as the definitive root cause at the time of Thorn's warning.

The self-custody hardware wallet market has operated for years on the premise that physical possession of a signing device eliminates the counterparty risk inherent in exchange custody. The implicit contract between hardware wallet manufacturers and their customers is straightforward: your keys are generated and stored securely on the device, and no remote actor can access them. If a fourth wave of attacks targeting a specific device has now materialized, that contract is under serious stress — regardless of whether the breach originates in hardware, firmware, or operational security failures at the user level.

Thorn's Warning and the Mempool Window

Thorn's intervention is notable not just for the scale he identified but for the operational guidance embedded in his warning. Unconfirmed Bitcoin transactions sit in the mempool — the network's waiting room — before miners include them in a block. During that window, it is theoretically possible to broadcast a conflicting transaction using replace-by-fee (RBF) mechanisms, potentially redirecting funds back to a wallet the legitimate owner controls. This is not a guaranteed remedy; it requires technical competence, access to the original wallet's private keys, and speed. But for victims who still retain functional access to their Coldcard and act immediately, it represents a non-zero chance of recovery.

The fact that a senior researcher at a major institutional crypto firm felt compelled to issue this guidance publicly speaks to the urgency. Thorn was not describing a theoretical risk — he was responding to active, in-progress transactions draining real funds from real users in real time.

Custody Risk in a Self-Sovereign World

The broader implication for the industry cuts in two directions simultaneously. On one hand, events like this will be cited by proponents of institutional custody and regulated exchange storage as evidence that self-custody carries risks that retail users are ill-equipped to manage. On the other hand, self-custody advocates will argue that the answer is better hardware security standards, more rigorous supply chain auditing, and open-source firmware verification — not a return to trusting centralized custodians who carry their own catastrophic failure modes.

Both arguments have merit, which makes the real lesson less about which custody model wins the ideological debate and more about the urgent need for the hardware wallet industry to treat security research with the same rigor applied to financial-grade infrastructure. Four waves of attacks against a single device brand should be a five-alarm event for every manufacturer in the space, not just Coinkite.

What This Means

For Coldcard users who have not yet been affected, the immediate priority is straightforward: verify the integrity of your device, consider moving funds to a freshly generated wallet on verified firmware, and monitor Thorn's public communications and the broader security research community for updates on the attack vector. For the industry, 389 Bitcoin swept across what appears to be a structured, multi-wave campaign is a data point that cannot be explained away as user error alone. It demands a thorough, transparent post-mortem from Coinkite and independent verification from the security research community. The credibility of hardware-based self-custody depends on it.

Written by the editorial team — independent journalism powered by Bitcoin News.