Coldcard attacker shifts $7.7 million in bitcoin from third theft wave
AI مارکیٹ کا خلاصہ
A Coldcard-related attacker moved 97.09 BTC (~$7.7M), routing funds through CoinJoin after earlier THORChain exits into ETH, underscoring ongoing laundering risk and renewed attention on UTXO taint dynamics. The exploit traces to a firmware RNG change that reduced seed entropy, with remediation requiring affected users to migrate to new seeds. Continued movement of stolen coins can pressure near-term market microstructure via elevated compliance and counterparty risk.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT-0.66%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
The hacker behind the Coldcard wallet exploit has moved 97.09 BTC tied to the third wave of thefts, worth roughly $7.7 million at Monday's prices. The transfer accounts for about 45% of that wave's take. Galaxy Research estimates that, across the full incident, 82% of the stolen bitcoin remains unmoved.
The first meaningful exit activity was observed on September 2, when about 20.5 BTC from the largest vault was routed through THORChain and reappeared as Ethereum. The bitcoin moved late Sunday was sent into CoinJoin rounds, a privacy technique that mixes multiple users' transactions to obscure links between inputs and outputs.
So far, only 20.56 BTC has reached Ethereum. Another 57.24 BTC remains unspent as CoinJoin change consolidated in a single address. Galaxy said the on-chain trail also ends for roughly 19 BTC.
Galaxy reported the attacker created 293 two-of-two multisig addresses and has been draining them in descending order by size. Eleven of those addresses are now empty. The next 10 addresses collectively hold 30.81 BTC, while the 233 smallest addresses hold 33.77 BTC.
Investigators trace the thefts to a firmware flaw introduced by Coinkite in March 2021. A change shifted seed generation away from the device's hardware random-number chip to a software substitute, cutting effective key strength from 128 bits of entropy to as low as 40 bits. That reduction made it feasible for attackers to reconstruct private keys offline and sweep single-signature addresses without accessing the hardware.
The sweeps began on July 30. Coinkite has since rebuilt the firmware, releasing updates Mk4/Mk5 5.6.2 and Q 1.5.2Q. The revised process requires users to add external randomness via key presses, dice rolls, or coin flips.
Coinkite warned that updating firmware cannot fix a seed created under the vulnerable version. Users who generated wallets on affected firmware need to create a new seed and move funds to the new wallet. Coinkite CEO Rodolfo Novak apologized in an open letter dated July 31, saying the company would need to earn back user trust. A full technical postmortem is still being prepared.
Galaxy also disclosed a previously unknown vault funded by 58 addresses. While it did not attribute the vault definitively, it said it likely represents another Coldcard victim. If confirmed, Galaxy's published exploit total would rise to about 1,806 BTC, or roughly $143.9 million.
In August, Galaxy said it was also tracking an unconfirmed fourth wave totaling 638.5 BTC, which would push the cumulative figure beyond 2,400 BTC. Galaxy added that it has not recorded any attacker sweeps since August 6.