Coldcard Attacker Moves $7.7M in Bitcoin

Coldcard Attacker Moves $7.7M in Bitcoin

Bitcoin linked to the Coldcard hardware-wallet exploit has started moving again, with approximately 97.09 BTC, worth around $7.7 million, transferred from addresses associated with the third wave of the attack. The movement represents roughly 45% of the Bitcoin attributed to that wave, adding a new laundering phase to an exploit that has already resulted in more than 1,700 BTC in confirmed losses.

The underlying breach originated from a firmware flaw that weakened the randomness used when generating wallet seeds. In its official Coldcard security advisory, manufacturer Coinkite confirmed that attackers were able to reconstruct vulnerable private keys offline without remotely compromising the physical devices. Any seed created on affected firmware remains at risk even after the device itself is upgraded.

Stolen Bitcoin Moves Through THORChain and CoinJoin

Analysis attributed to Galaxy Research indicates that the third-wave cluster was distributed across 293 two-of-two multisignature vaults. Approximately 97.09 BTC had been moved from those addresses by September 7, with the attacker reportedly processing larger balances before smaller ones.

The laundering sequence included cross-chain and privacy-enhancing tools. Funds began moving through THORChain on September 2, where Bitcoin could be swapped into Ether without relying on a centralized exchange, while subsequent transactions used CoinJoin techniques. Combining cross-chain swaps with CoinJoin increases the complexity of tracing the stolen funds, although the underlying transactions remain observable on public blockchains.

Galaxy previously reported at least 1,778.84 BTC stolen from 190 confirmed victims and more than 8,600 addresses. Most of the identified Bitcoin initially remained dormant in attacker-controlled wallets, while a smaller portion had moved into CoinJoin transactions, bridges or other on-chain routes as laundering activity developed.

The running total may continue to change as investigators identify additional victims. One newly associated cluster of 58 addresses could push estimated losses to approximately 1,806 BTC, although attribution remains preliminary. The scale of the exploit is therefore still being refined rather than represented by a single final loss figure.

Vulnerable Coldcard Seeds Require Migration

The vulnerability dates to a 2021 firmware change that caused seed generation to fall back to a software pseudorandom number generator instead of the intended hardware randomness source. Coinkite estimates that affected Mk2 and Mk3 seeds could contain roughly 40 bits of effective entropy, while Mk4, Mk5 and Q devices produced about 72 bits. That reduction made some seed phrases practical to reconstruct through offline brute-force searches.

Coinkite released corrected firmware beginning July 31, including version 5.6.0 or later for Mk4 and Mk5 and 1.5.0Q or later for Q devices. The company subsequently reinforced protections through additional releases. Installing fixed firmware protects newly generated seeds but does not restore the security of seeds created under vulnerable versions.

That distinction remains the most important operational issue for affected holders. Users whose seeds may have been generated during the vulnerable period need entirely new wallet seeds and must transfer assets to fresh addresses. The Coldcard incident demonstrates that hardware-wallet security ultimately depends not only on physical isolation but also on the integrity of the randomness used to create private keys.

Follow Us

Ads

Main Title

Sub Title

It is a long established fact that a reader will be distracted by the readable

Ads
banner 900px x 170px