It hasn't stopped yet, and as of today, it's still a threat.

The exploit was tied to a firmware bug introduced in March 2021 that weakened the randomness of seed generation on certain Coldcard devices. That vulnerability is still being actively exploited in waves .

text
Wave 1 (July 30): ~1,082 BTC (~$70M) from 1,196 addresses in 41 minutes
Wave 2 (Aug 1): ~1,158 BTC (~$75M) from 2,673 addresses
Wave 3 (Aug 2): ~1,367 BTC (~$88M) from 4,585 addresses
Wave 4 (Aug 3): +~449 BTC from 709 addresses
The total is now roughly 1,816 BTC (~$116M) from over 5,200 addresses, and additional sweeps are still happening .

The attackers are now multiplying. According to Galaxy Research, at least 15 independent parties are racing to claim vulnerable wallets . The sweep rate on August 3 spiked to 45 times normal baseline activity, meaning the thefts are accelerating, not slowing down .

Updating your Coldcard firmware alone will not fix this. The vulnerability is in the seed itself, and a patched device only protects newly generated seeds. Users who created a seed during the vulnerable window (March 2021 to mid-2026) must generate a brand-new seed after updating and migrate their funds immediately .

Users who generated a seed with at least 50 dice rolls or used a strong BIP-39 passphrase are considered safe . Everyone else, including multisig users if every signer was a vulnerable Coldcard, is still at risk .