
Coldcard Wallet Attacks Enter Fourth Wave, 449 BTC at Risk
A fourth wave of attacks targeting Coldcard hardware wallet users has put approximately 449 BTC at risk, according to on-chain analysis. Victims with pending transactions may still use Bitcoin's Replace-by-Fee feature to outbid attackers.
Key Takeaways
- 1## Attack Pattern and Scale Coldcard hardware wallet users are facing a fourth iteration of coordinated attacks, with on-chain data showing approximately 449 BTC currently exposed to theft attempts.
- 2The attacks exploit transaction malleability and low-fee transactions initiated by users, allowing attackers to intercept or redirect outgoing transfers before they confirm on the blockchain.
- 3## Why It Matters ### For Traders Users with unconfirmed BTC transactions from Coldcard should immediately check mempool status and consider RBF bumps to outbid attackers before confirmation.
- 4### For Investors Recurring wallet exploit waves damage hardware custody adoption and may push users toward custodial solutions, affecting long-term decentralization narratives.
- 5### For Builders Wallet developers should implement automatic RBF escalation, fee-bumping mechanisms, and transaction monitoring to mitigate mempool-level attacks.
Attack Pattern and Scale
Coldcard hardware wallet users are facing a fourth iteration of coordinated attacks, with on-chain data showing approximately 449 BTC currently exposed to theft attempts. The attacks exploit transaction malleability and low-fee transactions initiated by users, allowing attackers to intercept or redirect outgoing transfers before they confirm on the blockchain.
Why It Matters
For Traders
Users with unconfirmed BTC transactions from Coldcard should immediately check mempool status and consider RBF bumps to outbid attackers before confirmation.
For Investors
Recurring wallet exploit waves damage hardware custody adoption and may push users toward custodial solutions, affecting long-term decentralization narratives.
For Builders
Wallet developers should implement automatic RBF escalation, fee-bumping mechanisms, and transaction monitoring to mitigate mempool-level attacks.





