The latest wave of attacks on Coldcard hardware wallets has reportedly swept away 389 Bitcoin, raising alarms among users. Alex Thorn, head of research at Galaxy, highlighted a narrow window for some victims to recover their funds due to unconfirmed transactions still pending on the network.

What Happened

This appears to be the fourth major attack targeting Coldcard devices, known for their high security in storing Bitcoin. The breach exploited a vulnerability allowing hackers to initiate unauthorized transactions before victims could react. While the exact method remains unconfirmed, the attack’s scale suggests a coordinated effort, resulting in the loss of nearly 400 BTC, worth tens of millions of dollars at current prices.

What This Means for Coldcard Users

Thorn’s warning about unconfirmed transactions points to a brief chance for some users to intervene and potentially stop funds from leaving their wallets. This could involve quickly canceling or double-spending the transactions before they finalize on the blockchain. However, this opportunity is limited and requires swift action and technical know-how, leaving many users vulnerable.

The incident shows ongoing risks even with hardware wallets, often considered among the safest storage options. It also puts pressure on Coldcard’s developers to patch security gaps and reinforces the need for users to stay alert. Investors relying heavily on such devices must weigh the risks and consider additional safeguards.

This article is for informational purposes and does not constitute financial advice.