388.93 BTC reportedly stolen in suspected fourth wave of Coldcard attacks hitting 462 addresses

AI Market Summary
Monitoring suggests an organized Coldcard-related compromise, with 388.93 BTC swept from 462 addresses over ~2.5 hours and additional suspicious transactions pending in the mempool. The sharp rise in sweep activity and rapid second-hop movements indicate active laundering workflows, raising near-term security and custody risk perceptions. While not a protocol flaw, the event can pressure market sentiment by increasing concerns over hardware wallet supply-chain or firmware-boundary exploits.
Impact level
● High
Affected assets
BTC/USDT-0.43%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
ME News said Aug. 3 (UTC+8) that Galaxy's Head of Research monitoring indicates a coordinated Coldcard-related attack may be in progress, with additional similar transactions still awaiting confirmation in the mempool. Previously confirmed transactions show replace-by-fee (RBF) was enabled. Data from blocks 960,778 to 960,792 show 218 transactions over roughly 2.5 hours, involving 462 compromised addresses and 216 new destination addresses, moving a total of 388.92748828 BTC. None of the transactions included inputs older than the Coldcard firmware boundary. During the window, the sweep rate reached 13.8 per block versus a pre-incident baseline of 0.3 per block, a 45-fold jump. The transaction pattern was primarily 1:1, with each compromised address sending to a single new destination address. Only one destination address received two sweeps, and no aggregation addresses were observed. Some funds have already been forwarded to second-hop addresses. (Source: ODAILY)