Ly Gravity

Coldcard's Fourth Wave: 389 BTC Is Still Sitting in the Mempool, and That's the Only Alpha That Matters

CryptoRover Finance
I didn't react to the number. 389 BTC is not a headline number anymore. It's a rounding error in a market that clears tens of billions of dollars a day. What made my terminal freeze was the rest of the package: Alex Thorn, head of research at Galaxy, flagged what looked like a fourth wave of attacks against Coldcard hardware wallets. The stolen amount was quoted as 389 BTC. The alert mentioned something more specific and more dangerous: unconfirmed transactions. In the world of self-custody, an unconfirmed transaction is not a bug. It is a window. While the headlines screamed about ETF flows and range-bound Bitcoin, a handful of users were watching poisoned transactions crawl through the mempool. If you have ever tried to front-run a Uniswap transaction in 2020, you know what that window feels like. It is the thin space between broadcast and confirmation where the outcome is still undecided. The market treats that window as technical noise. For the people holding the affected private keys, it is the difference between losing everything and pulling the transaction back to safety. The report I read is thin. I can't verify its source. There is no timestamp, no original link, no named analyst other than Thorn. That missing metadata is itself a signal. A security alert that is both time-sensitive and unverifiable should not make you panic. It should make you stop signing transactions until you know your exposure. The lack of information is frightening precisely because the attack is described as the fourth wave. If this campaign has been running in waves, then either the defenses haven't learned anything, or the attack is hitting a part of the supply chain that doesn't get patched by firmware updates. Let's start with what Coldcard actually is, because the security model matters more than the brand. Coldcard is a Bitcoin-only hardware wallet from Coinkite, a Canadian company that has built its reputation on being the choice of paranoid Bitcoiners. It uses air-gapped QR codes, PSBT support, signed firmware, and a physical security checklist that makes Ledger look like a toy. Its users are not casual investors. They are people who can generate their own entropy, verify firmware hashes, and run their own node. This is the community that is supposed to be immune to the mistakes that drain exchange wallets. That makes the attack more important, not less. When a hardware wallet company loses its credibility with a technically elite user base, the damage echoes far beyond the victims. The entire self-custody narrative takes a hit. Bitcoiners have spent years telling newcomers that hardware wallets are the gold standard of security. The phrase 'not your keys, not your coins' was meant to end the debate. If a Coldcard can be compromised, the debate starts over from a much darker position. Now let's talk about the only technical clue that matters: unconfirmed transactions. Thorn's point was that some of the stolen funds might still be recoverable because the transactions have not been mined. That single sentence tells me more about the attack vector than any missing report does. If the attacker had stolen the seed phrase or broken the private keys, the coins would have moved immediately. The attacker would not leave a transaction sitting in the mempool for someone to notice. The funds would be gone in blocks, not hours. The fact that the attack is happening in the unconfirmed space suggests the compromise is in the transaction construction and signing flow. This is not a seed-generation attack. It is not a supply-chain attack that replaces the device with a fake wallet and waits for someone to type in a 24-word phrase. This is an address substitution attack, a malicious PSBT, or a corrupted companion tool. The user believes they are signing a transaction to their own address. The hardware device displays something plausible, or the user skips verification out of habit. The signature goes to the attacker's address instead. The transaction gets broadcast, and only then does the user notice that something is wrong. If that is the model, then the unconfirmed transaction is the victim's last weapon. The user still controls the private keys. The user can sign a competing transaction that spends the same inputs to a safe address and pays a higher fee. Miners will pick the transaction that gives them the most value. That is not Replace-By-Fee in the traditional sense. It is a double-spend race. The window closes when the attacker's transaction lands in a block. After that, the BTC belongs to whoever can mix, swap, or escape with it. I don't want to oversell the recovery angle. Executing a successful double-spend race requires technical precision, fast RBF signaling, and a deep understanding of Bitcoin's conflict rules. The average person who buys a hardware wallet to hold for five years does not know what CPFP means or why miners see conflicting transactions. If the victim is not comfortable with these tools, they should not attempt a rescue operation while panicking. The moment they start clicking random buttons on a fake 'Coldcard recovery' website is the moment the attack gets a second chance. Let's walk through the attack tree the way I would in a post-mortem. The first scenario is physical supply-chain interception. An attacker tampers with the device at the factory or during shipping. The compromised device contains a malicious firmware that swaps destination addresses after the user approves them. The user sees a normal transaction on the device screen because the operating system has already been modified. From the user's perspective, everything is fine. The first sign of trouble appears when the transaction never confirms, because the inputs and outputs do not look right. This scenario is terrifying because there is no software patch that can save a user who has already trusted a compromised device. The second scenario is a compromised companion application. Coldcard works with tools like Specter-Desktop or Electrum. If one of those dependencies is infected, an attacker can craft a PSBT that looks legitimate. The hardware wallet still does its job. The private keys never leave the secure element. But the human being is signing a transaction to the wrong address. This is the classic 'garbage in, garbage out' flaw. Hardware wallets protect private keys, but they do not protect the information that goes into the signing decision. The user is the last line of defense, and the user is a fallible human. The third scenario is a targeted supply chain attack on a specific batch. The fact that this is called the fourth wave suggests the attacker has a repeatable method. They are not phishing one weak user. They have a pipeline. They know which batch of devices is vulnerable, or they have compromised a distribution channel that keeps sending devices to high-value Bitcoiners. If that is true, then 389 BTC is just the known damage. The total exposure could be much larger. The affected devices could still be on shelves, in drawers, or being shipped to new customers right now. This is why the lack of official disclosure makes me angry. Coldcard users need to know if they are in the blast radius. They need batch numbers, firmware hashes, and a clear emergency update path. Instead, we have an analyst alert with no source attached to it. I don't blame Thorn for flagging it. I blame the industry-wide habit of treating security incidents as public-relations problems. The company that says 'we are investigating' without giving users immediate instructions is leaving those users in the dark. In a bear market, information is the only alpha. Without information, everyone defaults to panic. Alpha isn't in an altcoin chart or a yield farm. Alpha is in the order flow of a compromised transaction. If 389 BTC is still pending, a trained observer can see which inputs are being double-spent, which change addresses are getting swept, and which exchange deposit addresses start lighting up. That kind of flow data is more useful than any Bitcoin price forecast. It tells you whether the attacker is still active, whether the victims are waking up, and whether the stolen funds are about to hit a centralized exchange. Let's do the market math, because the immediate price impact is close to zero. 389 BTC is a tiny fraction of the 19.7 million BTC circulating. At $70,000 to $100,000 per coin, the loss is between $27 million and $39 million. That is a significant amount of money for the victims, but it is not enough to move Bitcoin's price. The market does not price a $30 million theft in an asset class that trades $30 billion a day. If the attacker dumps all of it, the order books absorb the volume and move on. The real damage is not the sell-side pressure. It is the moment when a sophisticated Bitcoin user starts questioning whether their hardware wallet is safe. That is the moment the market actually cares about. Hardware wallets are a small niche compared to Bitcoin itself, but their security assumptions sit underneath hundreds of billions of dollars of self-custody value. If users lose trust in Coldcard, they don't necessarily stop holding Bitcoin. They move to multisig, MPC, or custody. They change their backup strategy. They start asking for proof that their next hardware wallet was not tampered with during shipping. This type of behavioral shift is slow, invisible, and impossible to short. But it changes the structure of the industry in ways that matter more than one bad CPI print. The market doesn't fear the attack that is already priced. The market fears the second-order attack that nobody can see. If the compromise is in the supply chain, then every company that relies on overseas manufacturing needs to rethink its production process. The hardware wallet industry has been selling a simple promise: your private keys never leave the secure element. That promise is only as strong as the factory that assembles the device and the logistics company that ships it. A single malicious operator in the supply chain can compromise hundreds of devices without ever touching a digital network. This is a problem that cannot be solved with a firmware update. It has to be solved with physical inspection, tamper-evident seals, batch audits, and radical transparency. Here is the contrarian angle that most people are missing. The winners from this event will not be the hardware wallet companies that claim to have better chips. The winners will be the multisig and MPC providers who can honestly say that a single device failure is no longer a catastrophic risk. The 'one hardware wallet is enough' narrative is the real casualty. If this attack is confirmed as a fourth wave, then the security industry should stop treating single-device users as the default. The standard should become 2-of-3 multisig, with at least one signing key held in a geographically separate location. That standard is harder, more expensive, and less convenient. But it is the only honest answer to the chaos that a compromised hardware wallet creates. The other overlooked winner is the regulated custodian. Wall Street institutions have been buying Bitcoin through ETFs and custody products. They don't hold their own private keys. They never have to worry about whether a batch of Coldcard devices was tampered with. The attack reinforces their existing decision to outsource security entirely. That is not good for Bitcoin's self-custody ethos, but it is good for the share price of trusted custody companies. If the self-custody crowd starts losing confidence in hardware wallets, the funds flowing out of personal wallets will have to go somewhere. The most liquid exits are centralized exchanges and regulated custody desks. The retail narrative is usually 'not your keys, not your coins.' I think this attack exposes the flaw in that slogan. It's not enough to hold your own keys if your signing environment is compromised. A hardware wallet is not magic. It is a machine that signs what humans ask it to sign. If the display has been tampered with, if the input has been corrupted, or if the user is tricked into approving the wrong output, the private keys never save you. The keys are still safe. The user's trust is what gets stolen. I want to give you a practical playbook, because security analysis without action is just entertainment. First, if you use a Coldcard, stop signing large transactions until Coinkite publishes an official statement. Do not transfer coins out of precaution while panicking. Panic transfers are how people send funds to the wrong address or download malicious software. Instead, run a firmware hash check, inspect the device for physical tampering, and use a machine you trust. If anything feels off, build the new wallet in an isolated environment and move funds through a small test transaction first. Second, watch the mempool. If you believe your transaction might be poisoned, do not wait for a blog post. You need to find the transaction ID and assess whether it is still pending. If it is unconfirmed, you need to evaluate a competing transaction race. This is not a job for a casual user. Find someone who has worked with Bitcoin transaction mechanics, ideally someone who has rescued a stuck transaction before. The fee market is brutal, and the attacker is likely monitoring the mempool too. You don't get a second chance if the attacker sees your replacement strategy. Third, prepare for the phishing wave that follows every major security event. Scammers will send fake Coldcard emails with attachments, fake firmware updates, and fake recovery tools. They will mirror the official website and post on Twitter with verified-looking blue checks. The moment you are afraid is the moment you become vulnerable. Only trust the official Coinkite website, the official GitHub repository, and the official Coldcard firmware signing keys. Everything else is a trap. Fourth, after the dust settles, change your security architecture. The industry has known for years that a single hardware wallet is a single point of failure. This attack makes the argument impossible to ignore. Move your long-term Bitcoin into a multisig setup. Keep a small amount on a hot wallet for daily use. Use a separate hardware wallet for each signing key. Store seed material in fireproof, waterproof, physically secure locations. The inconvenience of multisig is the price of not depending on a single factory, a single shipper, and a single honest employee. I don't think the market should fear the next 24 hours. I think the market should fear the next 10 years. If hardware wallet users start abandoning self-custody because they no longer trust a physical device, the entire Bitcoin experiment loses one of its core principles. But the way to preserve self-custody is not to pretend that hardware wallets are infallible. It is to design systems that can survive a failure. Multisig was invented for this exact scenario. The people who ignore it are not brave. They are just uninformed. ETF approval wasn't the moment that institutional Bitcoin turned into a mature asset class. The maturity moment is now, when a security incident forces every serious holder to think about key management the way a treasury team thinks about audit controls. The old assumption was that buying a hardware wallet was the endpoint of security. The new reality is that security is a process, not a purchase. You don't reach safety by buying the most expensive device. You reach safety by testing your assumptions, verifying your backups, and planning for the moment when a trusted tool turns against you. The last thing I want to say is about the unconfirmed transaction as a metaphor. Bitcoin's security has always lived in that strange space between broadcast and confirmation. Miners decide which transaction wins. Humans decide what they are willing to sign. The attacker is not trying to crack math. The attacker is trying to exploit habits, trust, and convenience. That is the true fourth wave: not a cryptographic breakthrough, but a behavioral one. The tools that protect us are only as strong as the rituals we follow every time we sign. So watch the mempool. Watch Alex Thorn's account. Watch whether Goincite and other hardware wallet vendors start publishing batch-specific integrity checks. And most importantly, watch your own hands the next time you sign a transaction. The margin between losing 389 BTC and saving it is not measured in terahashes. It is measured in the seconds you spend looking at the screen before you press confirm. That is the raw material of the next wave, and the only defense that still works when everything else fails.

Coldcard's Fourth Wave: 389 BTC Is Still Sitting in the Mempool, and That's the Only Alpha That Matters

Coldcard's Fourth Wave: 389 BTC Is Still Sitting in the Mempool, and That's the Only Alpha That Matters

Coldcard's Fourth Wave: 389 BTC Is Still Sitting in the Mempool, and That's the Only Alpha That Matters

Market Prices

BTC Bitcoin
$63,944.6 +0.80%
ETH Ethereum
$1,872.76 -0.48%
SOL Solana
$74.01 +0.50%
BNB BNB Chain
$592.4 +0.63%
XRP XRP Ledger
$1.08 +0.05%
DOGE Dogecoin
$0.0705 -0.11%
ADA Cardano
$0.1947 +3.78%
AVAX Avalanche
$6.58 -0.08%
DOT Polkadot
$0.8220 +3.21%
LINK Chainlink
$8.24 -1.27%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$63,944.6
1
Ethereum ETH
$1,872.76
1
Solana SOL
$74.01
1
BNB Chain BNB
$592.4
1
XRP Ledger XRP
$1.08
1
Dogecoin DOGE
$0.0705
1
Cardano ADA
$0.1947
1
Avalanche AVAX
$6.58
1
Polkadot DOT
$0.8220
1
Chainlink LINK
$8.24

🐋 Whale Tracker

🔴
0xdb12...b801
5m ago
Out
4,680 BNB
🔵
0xde14...1c1c
2m ago
Stake
1,640,105 DOGE
🔵
0x73d7...59d1
2m ago
Stake
28,571 SOL

💡 Smart Money

0x0df7...4973
Experienced On-chain Trader
+$0.3M
60%
0x4f6e...e720
Experienced On-chain Trader
+$3.2M
92%
0x8741...d04e
Institutional Custody
+$0.3M
67%

Tools

All →