Golden Bitcoin symbol surrounded by network nodes
Crypto

Galaxy’s Alex Thorn flags likely Coldcard-linked BTC sweeps across 462 addresses

Thorn said some suspected attacker transactions are still unconfirmed, leaving a narrow fee-bump window for affected users.

By Emma Carter4 min read

Galaxy research head Alex Thorn flagged a fresh cluster of suspected Coldcard-related Bitcoin thefts that moved about 388.9 BTC across 218 transactions from 462 potential victim addresses. Thorn said some related spends are still sitting unconfirmed in the mempool, creating a time-sensitive chance for certain users to override the attacker’s transaction with a higher-fee conflict.

A New Cluster of Likely Coldcard Sweeps Hits 462 Addresses

Alex Thorn, head of research at Galaxy, flagged what he described as another wave of coordinated draining activity tied to Coldcard users, pointing to 218 transactions that moved around 388.9 BTC from 462 potential victim addresses over the last few hours.

Thorn framed the attribution as probabilistic rather than confirmed wallet-by-wallet identification, writing: “These are LIKELY Coldcard victims — they match the shape of coldcard vulnerable utxos and the elevated transaction pattern gives me high confidence they are another wave of attacks.” The “shape” reference is to UTXOs, or unspent transaction outputs, the discrete chunks of BTC that make up a wallet’s spendable balance.

The on-chain cadence is the tell. Thorn said the activity averaged 13.8 sweeps per block, around 45 times the rate observed in a pre-incident control window, which makes the flow look less like routine consolidation and more like a coordinated drain campaign.

The destination behavior also matters for tracking. Thorn said most transfers created a fresh destination address per victim rather than converging on a single obvious collection wallet, and that some funds had already been pushed into second-hop addresses, a common workflow when an attacker wants to reduce clustering and accelerate dispersion.

Why This Wave Matters for Traders Watching Stolen-Coin Flow

Mempool ‘Escape Hatch’: When a Higher-Fee Conflict Could Still Save Funds

The time-sensitive detail is that some suspected attacker spends are not final yet. Thorn said there are similar transactions sitting in the mempool, the pool of unconfirmed Bitcoin transactions waiting to be included in a block.

That creates a narrow “escape hatch” for a subset of affected users. Thorn said users who still control the relevant keys may be able to broadcast a conflicting transaction with a higher fee, sending funds to a secure wallet before the attacker’s transaction confirms. Mechanically, this is a replacement spend that pays miners more to confirm it first, invalidating the lower-fee version.

What to watch next is mostly block-by-block and operational:

1. Confirmation vs replacement: Whether the mempool-pending suspected sweeps confirm in the next blocks, or get replaced by higher-fee conflicting transactions from victims. 2. Sweep intensity: Whether the pace stays near Thorn’s cited 13.8 sweeps per block, or falls back toward the pre-incident baseline he referenced. 3. Second-hop churn: Whether the fresh per-victim destination addresses continue to push funds into second-hop addresses, which would imply rapid dispersion ahead of any exchange or OTC off-ramping. 4. Follow-on clusters: Whether additional waves are flagged in the days after this cluster, given Thorn’s framing that the pattern resembles prior attack activity.

The broader incident context remains the same. Thorn tied the activity to a previously disclosed Coldcard firmware flaw that caused affected devices to generate wallet seeds with less entropy than intended, and the latest estimates cited in the same account put the impact at thousands of wallets and over $90 million in Bitcoin stolen, though the methodology for those estimates was not detailed in the provided information.

What New Coldcard theft wave sweeps 389 Tells Me

The filing-equivalent detail here is the mempool status, not the headline BTC number. If attacker transactions are still unconfirmed, the threshold that matters is whether victims can actually get a higher-fee conflict mined first, because that is the difference between a post-mortem and a live mitigation window.

The 13.8 sweeps-per-block figure is also doing real work. If that pace persists and second-hop movement continues, the setup starts to look structural rather than narrative-driven, with an attacker workflow optimized for dispersion and harder real-time clustering. This matters in practical terms if the unconfirmed sweeps either confirm at scale or get replaced at scale, because that outcome determines whether this wave becomes realized sell-pressure risk or a contained incident.

Sources