Attackers launched a fourth wave of sweep attacks against bitcoin held in Coldcard hardware wallets on Monday. Estimated losses have reached roughly $114 million since Thursday. The latest transactions remained replaceable in the mempool, giving some victims a brief window to move their coins before the thefts.
How the sweep attacks work
Sweep attacks are a known threat for hardware wallet users. Attackers monitor the public mempool for transactions from Coldcard addresses. When a user broadcasts a transaction to move bitcoin, the attacker quickly broadcasts a competing transaction with a higher fee. Using replace-by-fee (RBF), the network prioritizes the higher-fee transaction, redirecting the coins to the attacker's wallet. The original transaction never confirms.
The attacker's transaction must have a higher fee per byte to be accepted by miners. In practice, attackers use fee estimation tools to outbid the victim's transaction by a small margin, making the replacement economical. Many wallets enable RBF by default, leaving users exposed.
The replaceable transaction window
In this latest wave, the attackers' own transactions were also replaceable. That gave victims a chance to fight back. By broadcasting a transaction with an even higher fee, some users could replace the attacker's transaction and reclaim their coins. The window is short — often just a few minutes — and requires active mempool monitoring. But it's a rare opportunity to reverse a sweep in progress.
Not all victims were able to act in time. The attackers likely used automated scripts to outbid any counter-transactions quickly.
Losses mount since Thursday
The attacks began Thursday and have escalated over the weekend. Monday's fourth wave pushed total estimated losses to $114 million. The first wave caught many users off guard. Subsequent waves showed the attackers were persistent. By Monday, they had refined their methods, making the fourth wave particularly effective. It's unclear how many individual wallets were hit, but the scale suggests a coordinated campaign targeting Coldcard users specifically. Coldcard is a popular hardware wallet known for its security features, but the attacks exploit a vulnerability in the transaction process, not the device itself.
What users can do
Coldcard users moving bitcoin can take steps to reduce risk. Using transactions with a high fee helps get confirmations quickly, leaving less time for attackers to intervene. Disabling RBF in the wallet settings prevents the transaction from being replaced entirely. Waiting for multiple confirmations before considering a transaction final is another safeguard.
The attacks are ongoing. The fourth wave is still active, and the mempool remains a battleground. Users are advised to stay vigilant and avoid relying on unconfirmed transactions for large sums.




