WeightChain

Market Prices

Coin Price 24h
BTC Bitcoin
$63,856.5 +0.88%
ETH Ethereum
$1,869.23 +0.07%
SOL Solana
$73.67 +0.46%
BNB BNB Chain
$591.7 +0.66%
XRP XRP Ledger
$1.08 -0.04%
DOGE Dogecoin
$0.0703 -0.20%
ADA Cardano
$0.1916 +1.16%
AVAX Avalanche
$6.53 -1.43%
DOT Polkadot
$0.8288 +3.66%
LINK Chainlink
$8.24 -0.99%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{年份}}
08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$63,856.5
1
Ethereum
ETH
$1,869.23
1
Solana
SOL
$73.67
1
BNB Chain
BNB
$591.7
1
XRP Ledger
XRP
$1.08
1
Dogecoin
DOGE
$0.0703
1
Cardano
ADA
$0.1916
1
Avalanche
AVAX
$6.53
1
Polkadot
DOT
$0.8288
1
Chainlink
LINK
$8.24

🐋 Whale Tracker

🔵
0xb3cf...171a
12h ago
Stake
494.51 BTC
🟢
0xadf4...3300
5m ago
In
4,700,384 DOGE
🔴
0xba29...ab17
2m ago
Out
2,007.92 BTC

💡 Smart Money

0x9903...e3b1
Market Maker
+$4.0M
71%
0xf645...cd2b
Early Investor
+$0.7M
92%
0xd77c...f0f9
Top DeFi Miner
+$3.5M
63%

🧮 Tools

All →

The Fourth Wave: 389 BTC and the Mempool's Narrow Window

Cobietoshi
Security
389 BTC sits in cryptographic limbo. Unconfirmed. Pending. Suspended between broadcast and finality in the mempool's gray zone — visible to the entire network, owned by no one until a block says otherwise. This is not a routine stuck transaction. Alex Thorn, head of research at Galaxy, has publicly flagged this cluster as part of a suspected fourth wave of Coldcard attacks. And the unconfirmed status may be the only reason affected users still have a path to recovery. The ledger does not lie, only the narrative does. Right now, the narrative is running several lengths ahead of the data. What we actually know fits on an index card. 389 BTC. Fourth wave. Thorn's warning. That is the complete file. No source link. No timestamp. No disclosed attack vector. No official Coinkite response. In my line of work, an information vacuum is itself a dataset — and it tells me that whoever published this either cannot share the details or has chosen not to. Coldcard occupies a specific ecological niche. This is not the Ledger of the masses; it is the hardware wallet of the bitcoin-native technical class. The users who compile their own firmware. Who verify seals and inspect PCBs. Who chose Coldcard precisely because Coinkite's design philosophy is uncompromising: the private key never leaves the secure element. No network connectivity in signing mode. Mandatory firmware signature verification. A threat model built on the assumption that the device itself is the last line of defense. The brand's own marketing language leans on phrases like "military-grade" and "unhackable" — which, in security terms, is equivalent to painting a target on the device. That assumption has now been tested four times. The first three waves receded without a definitive public post-mortem. This fourth wave is different in one material respect: the assets are still moving. Unconfirmed transactions mean the attack is either ongoing or incomplete — which means there is still a window. Technically, that window is a function of the mempool's replacement rules. Replace-By-Fee permits a transaction to be superseded by a higher-fee version broadcasting from the same inputs. Child-Pays-For-Parent allows an unconfirmed parent to be accelerated by spending its outputs in a high-fee child. Both are legitimate emergency tools. Both require two things the average user does not have in the heat of a hack: the private keys and the technical composure. In 2017, when I spent six weeks tracing PlexCoin's wallet clusters for a forensic audit, I learned that the difference between recovering funds and losing them is almost always measured in hours. The same arithmetic applies here. But there is a catch: if the attacker controls the signing environment, they control the keys — and the window closes before it opens. The unconfirmed transaction clue narrows the attack surface considerably. For funds to be sitting in the mempool, one of three failure points has been breached. Vector one: the supply chain. Coldcard devices ship from Coinkite's manufacturing partner through a global logistics network. Interdiction attacks — where devices are intercepted, compromised, and re-sealed in transit — are the classic hardware wallet threat model. A modified device could contain malicious firmware that appears legitimate, signs a valid-looking transaction, and sends coins to an attacker's address. The user sees a plausible address on the screen. The signature is valid. The error only becomes apparent when the funds land where they should not. Vector two: the firmware boot path. Coldcard is known for mandatory firmware signature verification. If an attacker has obtained a signed firmware image or found a validation bypass, they can install persistent malware on the device. This is the most technically sophisticated vector, and it requires either a compromised signing key or a cryptographic flaw — neither of which has been publicly demonstrated in this wave. Vector three: the companion software layer. Most Coldcard users interact with their device through Specter-Desktop, Electrum, or similar wallet software. A compromised desktop environment can swap receiving addresses at signing time. The hardware wallet signs what it sees on its screen; the user confirms what they see on their screen; the transaction goes to an address nobody actually verified. I have been mapping these attack vectors the way I mapped yield vectors before the DeFi Summer peak — tracing the paths, measuring the incentives, looking for the divergence between a system's assumptions and its implementation. The uncomfortable conclusion is that all three vectors converge on the same structural weakness: the secure element is secure. The system around it is not. The same principle held in May 2022, when I deployed a real-time dashboard to trace the Terra/Luna stability collapse. The protocol did not fail because the validators were malicious. It failed because the incentive structure had a design flaw masked by a compelling narrative. A hardware wallet that is secure by design can still fail at the intersection of manufacturing, logistics, and human behavior. Now let us talk about the number itself. 389 BTC. At current market rates, that is approximately $25 to $39 million. Against Bitcoin's circulating supply of roughly 19.7 million coins, it is 0.000002 percent. Bitcoin's daily spot volume regularly clears $10 billion, and the derivatives layer multiplies that figure several times over. Even if the attacker dumps the entire haul into the order books at once, the price impact would be negligible and transient. That is the wrong number to obsess over. The right number is the one nobody can calculate: the size of the exposed device population. If this is a supply chain attack, it affects not just the 389 BTC already in motion but every Coldcard device from the same manufacturing batch or distribution channel. An inventory of compromised devices is worth an order of magnitude more than a single fund trace. This is why Thorn's warning matters. Galaxy does not typically comment on consumer hardware wallet attacks. When an institutional research desk flags a security event, it is usually because there is institutional exposure somewhere in the picture. The 389 BTC may be the visible tip of a larger, still-unquantified problem. The market mechanics are straightforward. A confirmed supply chain attack would accelerate the migration to multisig and MPC threshold signature schemes — not because those schemes are immune to hardware compromise, but because they reduce any single device's blast radius from catastrophic to survivable. A 2-of-3 multisig distributing keys across a Coldcard, a phone, and a hardware security module survives the compromise of any one component. MPC schemes split the key into shares that never physically reunite. Both are rational responses to the lesson this event is teaching. The narrative consequence is less rational. The "hardware wallet equals absolute security" story has been a marketing cornerstone for the entire industry, and it was never technically true. Hardware wallets reduce risk; they do not eliminate it. The device can be intercepted. The supply chain can be corrupted. The human using it can be phished. When a product is marketed as a fortress, it becomes an attractive target — and its first breach reads as total failure rather than a known limitation. Here is the contrarian angle, and it cuts both ways. The "Coldcard is compromised, hardware wallets are finished" interpretation is wrong. The "this is just a rumor, ignore it" interpretation is equally wrong. The reality is more precise and less comfortable: the attack may have nothing to do with Coldcard's design and everything to do with the physical and digital infrastructure around it. Supply chain interdiction does not discriminate between vendors. Ledger, Trezor, BitBox — they all ship through the same logistics networks, rely on the same manufacturing partners, and trust the same authentication mechanisms. The difference is that Coldcard's technical user base possesses the skills to detect the anomaly and the platform to amplify it. Also note what is missing from the report. I have been burned by unverifiable security claims before, and any analyst who claims otherwise is either new or dishonest. The report has no source, no link, no timestamp. It could be a coordinated attempt to seed fear and drive users toward a competitor. It could also be a credible but carefully stripped warning released to avoid tipping off the attackers. The mempool data will tell us which — but only if we read it correctly. An unconfirmed transaction flagged by one research desk is a lead, not a conclusion. The next 72 hours will be decisive. Watch the 389 BTC: if the cluster consolidates and moves through a mixer or an exchange, the attack is real and the wave is still rolling. Watch Coinkite's response window: silence beyond 72 hours is itself an answer. Watch the multisig providers: a volume spike in new vaults would confirm the market has absorbed the lesson. The question was never whether your Coldcard is compromised. The question is whether you can verify that it is not — and that is a supply chain question, not a hardware one.