Cointelegraph reports that a suspected fourth wave of attacks on Coldcard wallets has resulted in the theft of 389 Bitcoin, according to Galaxy research head Alex Thorn. Thorn warned that unconfirmed transactions may give some affected Coldcard users a narrow window to recover their funds.
If this holds, it points to a supply-chain or firmware-level compromise pattern rather than isolated user error, which is the scenario hardware-wallet integrations should stress-test against. Worth checking whether the exploit path touches how transactions are constructed or signed, since anything affecting unconfirmed txs has implications for how your app surfaces mempool state and warns users before broadcast. For anyone building custody or signing flows, treat the narrow rescue window as a reminder to give users a clear, fast path to move funds when a device is suspected compromised.
The headline and summary above belong to Cointelegraph; the full story is theirs and lives on their site. Only the commentary is ours.