Loading prices…
STKR NewsSTKR News0 of 3 free this month
Markets

Coldcard wallet losses may near $114 million as possible fourth sweep emerges

A massive security breach targeting Coldcard users could reach $114 million in losses. For builders, it is a reminder that even hardware security has human and software failure points.

Originally on CoinDesk
AB

Adrian Boysel

Contributor

Aug 3, 2026

4 min read

Photo illustration / STKR News

We have spent years telling people that if they want to be their own bank, they need a hardware wallet. It is the gold standard. But lately, that standard is looking a bit tarnished. A significant ongoing security incident involving Coldcard wallets has now escalated, with estimates suggesting total losses could climb toward $114 million. This is not just a rounding error; it is a systemic shock to the idea of 'air-gapped' safety.

The Anatomy of the Sweep

The situation is fluid, but the mechanics are grimly familiar. A series of 'sweeps' has been draining funds from affected wallets. We are currently looking at the potential for a fourth wave of these automated thefts. The attacker is essentially identifying vulnerable addresses and moving everything to a new destination. This is not a slow leak; it is a high-speed siphon.

What is particularly interesting from a technical standpoint is the use of Replace-By-Fee (RBF). For the uninitiated, RBF allows a sender to replace a pending transaction with a new one that pays a higher fee. In this context, it has turned into a desperate race. If a user spots their address in the mempool with a pending unauthorized transaction, they technically have a window—minutes, usually—to broadcast their own transaction with a higher fee to move the funds to a safe harbor before the attacker's transaction is confirmed.

It is a digital version of a bank robbery where the vault door is opening slowly, and the owner and the thief are both grabbing for the handle at the same time. For most retail users, this is an impossible task. They aren't monitoring the mempool 24/7, and they certainly don't have the technical tooling ready to execute a manual RBF maneuver under pressure.

Hardware is Not a Silver Bullet

As a founder, I look at this and see a massive UX failure in the security stack. We have marketed these devices as 'set it and forget it' vaults. The reality is that the gap between the hardware and the user's actual security posture is often filled with fragile software and human error. Whether this turns out to be a supply chain attack, a firmware vulnerability, or a sophisticated social engineering campaign, the result is the same: the 'cold' in Coldcard did not keep these funds from burning up.

We have to stop pretending that air-gapping is a magic spell. If the process of signing a transaction—even offline—can be compromised, the physical isolation of the private keys becomes a moot point. Builders need to realize that the more complex we make these 'secure' workflows, the more places there are for things to break. We are adding layers of friction that users tolerate for the sake of safety, but if the safety fails, the friction was for nothing.

What This Means for Builders

If you are building in the wallet space or the security infrastructure layer, this incident is your roadmap of what to fix. We need better alerting systems that don't require a computer science degree to understand. The fact that 'watching the mempool' is the only defense right now is an indictment of our current tooling.

  • Real-time Monitoring: Users shouldn't have to manually check the mempool. Wallets should have automated 'panic' features that detect unauthorized outbound attempts and offer one-click RBF counters.
  • Simplicity Over Paranoia: We often prioritize theoretical security over practical usability. If a device is so secure that a user cannot tell when it has been compromised, is it actually secure?
  • Account Abstraction: This incident highlights why we need to move away from pure EOA (Externally Owned Account) models. Programmable security, like social recovery and daily spending limits, would have blunted the impact of these sweeps significantly.

The Skeptical Take

I have seen this movie before. A hardware provider faces a crisis, the community gets angry, and then we all go back to the same habits because there aren't many better alternatives. But $114 million is a loud enough number to maybe change the conversation. We are seeing the limits of the first generation of hardware security.

Is Coldcard solely to blame? It is too early to point fingers at the silicon, but the brand damage is already done. In crypto, trust is the only real currency, and once you lose it, the exchange rate to get it back is astronomical. We should be asking why these addresses were targeted specifically and how the attacker gained enough confidence to execute multiple waves of sweeps without being blocked.

The industry keeps building faster cars without thinking about better brakes. This incident is a high-speed crash that shows exactly where the seatbelts failed.

Final Thoughts for Founders

Do not just watch this from the sidelines and think, 'Glad it wasn't my protocol.' The fallout from these events affects the entire ecosystem. It hardens the narrative that crypto is 'too dangerous' for the average person. If the most 'hardcore' security tools can result in a hundred-million-dollar loss, we have a long way to go before we can talk about mass adoption.

Focus on building systems that fail gracefully. If a private key is compromised, there should be a second line of defense that doesn't involve a high-stakes bidding war in the mempool. Until we solve that, we are just building very expensive glass houses.


Read the original at CoinDesk →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses