Losses tied to a wave of Coldcard wallet compromises are approaching $114 million as on-chain watchers flag what could be a fourth coordinated sweep of affected addresses, extending an incident that has already drained thousands of Bitcoin holdings.
What the reported near-$114 million in losses means
The running tally of stolen funds is now nearing $114 million, up from earlier estimates as newly identified movements are folded into the count. The figure is an observed, still-rising total rather than a final accounting. For related coverage, see Bybit to Suspend Zircuit (ZRC) Deposits and Withdrawals on August 4, 2026.
Just a day earlier, the attack had spread across roughly 4,500 addresses with losses near $89 million, underscoring how quickly the incident has escalated within a single 24-hour window. For related coverage, see Bybit schedules UNITREEUSDT perpetual pre-market listing for August 3, 2026.
Wallet sweeps matter in incident coverage because they show funds being consolidated and moved out of victim addresses, often a signal that private keys or seeds are already compromised rather than merely at risk. The scale here has drawn attention precisely because Coldcard is marketed as a hardware cold-storage device. For related coverage, see U.S. Jobs, Circle, Galaxy, American Bitcoin Earnings: Crypto Week Ahead.
Why a possible fourth sweep is drawing scrutiny
Trackers have flagged a possible fourth wave that reportedly moved a further 448 BTC, adding to three earlier rounds of movement. The wave remains unconfirmed, and observed wallet activity is not the same as verified attribution of who controls the receiving addresses.
What makes the latest movement notable is its timing and clustering: it follows the same pattern of batched transfers seen in prior sweeps, suggesting the same actor or toolkit rather than isolated thefts. Analysts typically watch next for consolidation into exchange deposit addresses or mixers.
The primary on-chain reporting has been surfaced publicly through the account @intangiblecoins on X, which has been documenting the address movements as they emerge. Readers should treat single-source tracking as provisional until independently corroborated.
What repeated sweeps mean for Coldcard users
Repeated sweeps deepen concern because each new wave signals the compromise is ongoing, not contained, leaving holders uncertain whether their own device or seed handling is exposed. The episode follows earlier warnings after a reported 594 BTC theft affecting Coldcard Mk3 users.
The incident has also featured in broader industry roundups, including coverage that highlighted the Coldcard exploit in an August 2 digest, a sign of how much attention the case is drawing across the market.
For users of hardware wallets, the practical takeaway is around confidence in custody and seed security rather than any single fix, and the story remains one to watch as tracers verify whether a fourth sweep is confirmed and where the funds ultimately land.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
