389 Bitcoin May Already Be Gone: Coldcard Users Have a Narrow Window to Act Now

A suspected fourth wave of Coldcard wallet attacks has swept 389 Bitcoin from victims' hands, and Galaxy Research head Alex Thorn says some users may still have a razor-thin chance to stop the bleeding.

Thorn went public with a warning that unconfirmed transactions, those still sitting in the mempool and not yet settled on-chain, could give targeted Coldcard holders a brief window to intervene before their funds vanish permanently. The operative word here is brief. Mempool transactions do not wait.

What Is Actually Happening

This is not a software bug. It is not a phishing link. The attack pattern targeting Coldcard users has now surfaced across what appears to be a fourth distinct wave, suggesting a coordinated and ongoing threat rather than a one-off exploit. The total confirmed loss across suspected incidents is climbing, with 389 Bitcoin representing the latest recorded drain.

Coldcard is widely regarded as one of the most secure hardware wallets in the Bitcoin ecosystem, favored by self-custody advocates and high-net-worth holders precisely because of its air-gap capabilities and open-source firmware. That reputation is now being stress-tested in real time.

Details on the precise attack vector remain unconfirmed, which is the most unsettling part. When security researchers cannot fully characterize how funds are being taken, the threat surface is undefined. That uncertainty is exactly what makes this situation dangerous for anyone holding Bitcoin on a Coldcard device.

The Unconfirmed Transaction Opportunity

Thorn's warning centers on one specific technical reality: transactions broadcast to the Bitcoin network are not final until they are confirmed in a block. If an attacker has initiated a transfer but it remains unconfirmed, the rightful owner may be able to use replace-by-fee techniques or other mempool tools to broadcast a competing transaction that sends funds to a safe address first.

This window is narrow, unpredictable, and not guaranteed. Network congestion, miner priority, and timing all play a role. But for any Coldcard user who has noticed suspicious outbound transaction activity, the time to act is not tomorrow.

What You Should Watch and Do Right Now

- Check your mempool. If you use a Coldcard, verify no unauthorized outbound transactions are pending using a block explorer tied to your wallet addresses. - Move funds proactively. If anything looks off, initiate a transfer to a clean wallet immediately, prioritizing a high fee to front-run any attacker transaction. - Do not wait for confirmation. The community is still piecing together the attack vector. Waiting for official guidance may cost you the window Thorn is describing.

The broader signal here is harder to ignore: even the most trusted hardware wallets are under active, evolving pressure. Self-custody remains the standard, but complacency is now a liability. Watch Thorn's feed and the Coldcard GitHub closely over the next 48 hours.