A wave of thefts targeting users of the Coldcard hardware wallet has pushed potential losses toward $114 million, with security researchers now tracking what may be a fourth large-scale draining event.
## A Growing String of Attacks The apparent fourth sweep adds to a series of incidents that have already drained substantial sums from Coldcard-linked addresses. If confirmed, the cumulative damage would approach $114 million, marking one of the more significant hardware wallet-related loss events in recent memory.
Investigators monitoring blockchain activity flagged the latest suspicious movement of funds after spotting a pattern of coordinated transactions consistent with earlier attacks. The mechanics of how affected users' keys or devices were compromised remain under scrutiny.
Anyone who spots their own address queued in the mempool has only minutes to act before the funds vanish.
## The Replace-by-Fee Window A critical wrinkle in the situation involves the way the pending transactions are structured. Because they signal replace-by-fee, victims who catch their address sitting in the mempool have a narrow opportunity to fight back. By broadcasting their own transaction with a higher fee, they can attempt to move their coins to safety before the attacker's transaction confirms.
That window is extremely tight, however. Once a competing transaction with a lower fee is displaced, the race comes down to which transaction miners confirm first. For most users, the difference between recovery and total loss may come down to mere minutes of vigilance.
## What Users Should Watch For Security-conscious holders are being urged to monitor their addresses closely and prepare to respond quickly if they see unauthorized activity. The episode underscores the stakes of hardware wallet security, even for tools marketed on their robust protections.
- Watch the mempool for any pending transactions tied to your address.
- Be ready to broadcast a higher-fee replacement transaction to reclaim funds.
- Treat the replace-by-fee window as a matter of minutes, not hours.
As researchers continue to piece together the scope of the attacks, the total figure could shift as more addresses are analyzed and any additional sweeps come to light.
