1,816 BTC drained. 5,294 addresses. Four waves in five days. The Coldcard exploit is not just a hardware bug. It is reversing the post-FTX self-custody narrative. Net BTC now flows from self-custody to exchanges and institutional custodians for the first time since Nov 2022.
🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS pattern identified: blocks 960,778 - 960,792 (last ~2.5 hours, still going): • 218 transactions, 462 victim addresses, 216 fresh destinations. • 388.92748828 BTC • EVERY one has ZERO inputs predating the Coldcard firmware boundary • Rate 13.8 sweeps/block vs 0.3/block in a pre-incident control window = ~45x elevated • Topology is 1:1 — one fresh destination per victim, only ONE destination received two sweeps. No collector funnel. • Some funds have already been swept into 2nd hop addresses. these are LIKELY Coldcard victims -- they match the shape of coldcard vulnerable utxos and the elevated transaction pattern gives me high confidence they are another wave of attacks MOVE YOUR FUNDS OFF COLDCARD DEVICES ASAP AND USE HIGH TX FEES more details to come as this takes shape
· 59 Views