started · updated
Coldcard wallet hack: Attacker moves 45% of stolen Bitcoin
The attacker behind the Coldcard hardware wallet exploits has begun moving a significant portion of stolen funds. According to Galaxy Research, approximately 45% of the Bitcoin stolen during the third wave of attacks has been moved, including roughly 97.09 BTC valued at approximately $7.8 million.
To obscure the transaction trail, the hacker has utilized THORChain to swap Bitcoin for Ether and employed CoinJoin techniques to bundle transactions. The attacker appears to be targeting the largest vaults first, moving funds from vaults #1 through #11 while leaving smaller vaults untouched.
The breach stems from a firmware vulnerability in Coinkite-provided software released in 2021. The flaw caused certain Coldcard devices to use a software-based pseudo-random number generator instead of the hardware generator, resulting in wallet seeds with insufficient entropy. This allowed attackers to potentially reconstruct private keys through brute-force methods. While Coinkite has since patched the firmware, any seeds generated during the vulnerable period remain compromised. Total confirmed losses from the exploit chain are estimated at approximately 1,789 BTC across more than 8,865 addresses.