📝 Executive Summary
Galaxy research head Alex Thorn warned that unconfirmed transactions may give some Coldcard users a narrow opportunity to save their funds.
Galaxy's Alex Thorn warns of a fourth Coldcard attack wave that has already swept 389 BTC, urging users to monitor unconfirmed transactions for a chance to save funds amid the ongoing hardware wallet exploitation.
The article reports a security breach where 389 BTC were stolen from Coldcard wallets, with Galaxy's Thorn warning that unconfirmed transactions may allow some users to salvage funds. This directly impacts Bitcoin's security narrative and could prompt selling pressure if stolen coins are dumped on exchanges, or uncertainty if users lose confidence.
The theft of 389 BTC could exert selling pressure if attackers dump coins on exchanges, though the amount is relatively small. More importantly, the security breach erodes trust in hardware wallets, potentially dampening investor sentiment in the short term.
While this attack targets Coldcard specifically, it raises concerns about the security of all self-custody solutions. Users should verify their transaction signatures and consider additional security measures regardless of wallet brand.
Thorn's warning emphasizes monitoring unconfirmed transactions and possibly using fee-bumping to outpace attackers. In general, users should keep firmware updated, verify receiving addresses, and avoid signing transactions on compromised devices.
Galaxy research head Alex Thorn warned that unconfirmed transactions may give some Coldcard users a narrow opportunity to save their funds.
Galaxy Digital's Alex Thorn reported that a suspected fourth wave of attacks on Coldcard hardware wallets has resulted in the theft of 389 Bitcoin. The attackers are exploiting a vulnerability, and Thorn warned that unconfirmed transactions might give users a limited chance to save their funds.
Thorn suggests that users with unconfirmed transactions may be able to salvage their Bitcoin by monitoring the network and possibly using fee-bumping techniques to accelerate confirmations before attackers can finalize the theft.
It highlights ongoing vulnerabilities in even the most trusted hardware wallets, raising concerns about the broader self-custody model and potentially eroding user confidence in storing large amounts of Bitcoin offline.