A suspected fourth attack wave targeting Coldcard hardware wallets has been detected, with 389 Bitcoin involved. Galaxy Digital's head of research, Alex Thorn, warned about the attack wave, noting that unconfirmed transactions may give some Coldcard users a narrow opportunity to save their funds. The threat appears to be ongoing.
What we know about the attack
This would be the fourth known wave targeting Coldcard devices. The previous three waves collectively drained thousands of Bitcoin from users who believed their funds were safe in cold storage. This time, 389 BTC — worth roughly $25 million at current prices — is at risk. Thorn's warning came via social media, urging users to act fast.
The narrow window
Thorn pointed to unconfirmed transactions as the key detail. Some Coldcard users may still have a chance to move their funds before attackers finalize the theft. But the window is tight. If a transaction hasn't been broadcast yet, or if it's stuck in the mempool, there's a small opening. Users need to check their wallets immediately.
Who's behind the warning
Alex Thorn leads research at Galaxy Digital, a major crypto financial services firm. He's been tracking Coldcard-related attacks closely. His public alert this week is the most detailed signal yet that the threat isn't over. Thorn didn't name a specific attacker or group, but the pattern matches earlier waves.
What users should do now
Anyone using a Coldcard should check for unconfirmed outgoing transactions they didn't authorize. If they see one, they should try to replace-by-fee or contact their wallet provider. For those who haven't been hit yet, moving funds to a new seed — generated on a clean device — is the safest bet. The next few hours could decide whether that 389 BTC stays lost or gets saved.




