A fourth wave of Coldcard hardware wallet hacks has just swept 448.7 BTC from 709 user addresses. Galaxy Research researcher Alex Thorn identified this latest streak of attacks on August 3, 2026. He noted an average surge of 13.8 sweeps per block - a volume that skyrocketed 45-fold compared to normal periods before the incident began.
The situation on the ground is growing increasingly complex as some victims’ funds have already been moved to a second transit address. The hacker deliberately employed this pattern to obscure the trail. In total, these four consecutive waves of attacks are estimated to have drained 1,815.75 BTC from 5,294 different wallets, although this composite figure has not yet received final confirmation from all parties. Retail panic was inevitable. Just before this fourth wave was detected, daily Bitcoin transfers in denominations under 1 BTC surged drastically, involving 39,600 BTC - the highest level since the collapse of the FTX exchange in November 2022.
Why the Encryption Keys Were Guessable
The root of this crisis stems from a fatal flaw on the production side. Coinkite traced the issue to a March 2021 firmware update. The code changes at that time incorrectly routed the new wallet generation function to the weaker MicroPython pseudo-random number generator (PRNG). This occurred despite the device being designed to draw pure entropy from a hardware-level True Random Number Generator (TRNG).
This routing error had costly consequences. Mk2 and Mk3 wallets manufactured with this flawed code had only 40 bits of effective entropy. Meanwhile, newer generations like the Mk4, Mk5, and Q devices only possessed 72 bits, far below the absolute 128-bit standard that should protect users’ wealth. Only those who generated their keys from the start using physical methods - namely a minimum of 50 fair and private dice rolls - are immune to this vulnerability.
For Kraken Chief Security Officer Nick Percoco, the series of hacks serves as a reminder for the crypto industry. He noted that security auditors have so far only verified whether the hardware random number generator module is present, rather than testing whether the production firmware actually calls that function when a wallet is created. As it turns out, the hardware wallet industry lacks rigorous standard processes comparable to those of the conventional payment industry, such as NIST SP 800-90B or BSI AIS-31 guidelines.
The Final Rescue Window in the Mempool
Amidst the ongoing mass theft, a narrow path remains for victims whose transactions are still queued in the Bitcoin mempool. Thorn warned that there are several hacker transactions that have not yet been confirmed by miners. Users who feel vulnerable and still hold their original keys can attempt to front-run the hacker’s moves. To do this, they must immediately broadcast a new transaction with a significantly higher network fee - via the Replace-by-Fee mechanism - so that their funds are routed to a safe wallet.
For owners whose assets remain untouched, Coinkite has already patched the security vulnerability with firmware release version 4.2.0 for Mk2/Mk3 models, 5.6.0 for Mk4/Mk5, version 1.5.0Q for the Q series, and 6.6.0X/6.6.0QX for the Edge variants. However, updating the device to these versions will not fix keys that have already been generated with weak entropy. Users must create a new key seed from scratch on the updated device, verify the address, send a small test balance, and then transfer all of their old funds.
Facing the prolonged fallout of this 2021 flaw, Coinkite immediately halted all shipment schedules. Their factory also took the extreme step of destroying every hardware unit that had already been installed with the problematic firmware at their production facility.
As reported by crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.