A fourth wave of sweeps targeting bitcoin addresses generated by Coldcard hardware wallets is underway, with researchers now estimating total losses at approximately 1,816 BTC — roughly $114 million — across more than 5,200 addresses since the attacks began on July 30.

Galaxy Research's head of firmwide research, Alex Thorn, flagged the latest wave early Monday, noting a critical difference from prior sweeps: the attacker has opted into Bitcoin's replace-by-fee mechanism, meaning the pending transactions can theoretically be overridden before confirmation.

How Replace-by-Fee Changes the Equation

Replace-by-fee is a Bitcoin protocol feature that allows a pending transaction to be replaced by a later one that pays a higher mining fee. Until a transaction is confirmed in a block, a victim who discovers their address in the mempool — the queue of unconfirmed transactions — can submit a competing transaction with a higher fee, incentivizing miners to process theirs first.

This creates a narrow but unprecedented window for affected users. Previous waves consolidated stolen funds rapidly into shared collector addresses within minutes, leaving victims no time to react. The fourth wave's use of replace-by-fee suggests the attacker is taking a different approach, possibly due to the diminishing value of remaining vulnerable addresses.

Revised Loss Estimates

The fourth wave targeted blocks 960,778 through 960,792, hitting 462 victim addresses across 218 transactions — approximately 14 sweeps per block, compared to 0.3 per block in a pre-incident control window. That represents roughly 45 times the normal rate of address drainage.

On the revised count, the fourth wave took approximately 449 bitcoin from 709 addresses. The cumulative total across all four waves now stands at 1,816 BTC from over 5,200 addresses, valued at approximately $114 million at current prices.

Evolution of the Attack

Each successive wave has shown tactical refinement. The first wave was blunt and aggressive — 1,083 bitcoin taken from 1,196 addresses in 41 minutes, with funds sent to a handful of shared collector addresses. The second wave followed a similar pattern but targeted a broader set of addresses.

By the third wave, the attacker shifted to sending each victim's coins to unique destination addresses rather than shared collectors, making blockchain analysis significantly more difficult. Funds were also parked in pay-to-witness-script-hash outputs, which can carry multisignature or timelock conditions.

The fourth wave continues this dispersion strategy, with each victim's coins routed to previously unused addresses. None of the sweeps have touched multisignature setups, consistent with the vulnerability affecting only single-key seeds generated by the flawed March 2021 firmware.

What Affected Users Should Do

Anyone who generated a wallet seed using a Coldcard device running the affected firmware should treat those wallets as compromised. Funds should be moved immediately to a new wallet generated with unaffected firmware or a different hardware wallet entirely.

For those who believe their funds may be caught in the current replace-by-fee transactions, checking the mempool for their addresses is critical. If an address appears in an unconfirmed transaction, submitting a competing transaction with a higher fee could potentially recover the funds before the attacker's transaction is confirmed.

Coldcard manufacturer Coinkite has released emergency firmware for every affected model but has not yet issued a formal statement on the fourth wave of exploits.