Coldcard hardware wallet users may have lost nearly $114 million in a series of fund sweeps, with a possible fourth sweep now detected. The pending transactions use replace-by-fee (RBF), a feature that lets users bump fees to move funds first if they spot their address in the mempool.
How the sweeps work
The losses stem from repeated unauthorized transfers out of Coldcard wallets. Investigators tracking the blockchain have identified three previous sweeps that together account for the $114 million figure. The fourth potential sweep appears as a set of pending transactions, though it is not yet confirmed whether the funds have moved.
The RBF twist
Replace-by-fee is a Bitcoin feature that allows a sender to replace an unconfirmed transaction with a new one that pays a higher fee. In this case, the pending transactions are using RBF, meaning the attacker could still be in the process of moving the funds. But the same mechanism gives affected users a narrow window: if they spot their own address in the mempool, they can issue their own RBF transaction with a higher fee to redirect the funds back to themselves.
What users can do
Coldcard wallet owners are being urged to monitor the mempool for any transactions involving their addresses. If a pending transaction appears, they can attempt to override it by broadcasting a new transaction with a higher fee. The window is short — once the attacker's transaction confirms, the funds are gone. The company has not issued a public statement about the latest sweep, and the identity of the attacker remains unknown.
The total losses could climb if the fourth sweep completes. For now, the blockchain shows the pending transactions waiting for confirmation, and the clock is ticking for anyone who might still have a chance to act.




