Coldcard attack continues; users urged to move funds from affected addresses

icon MarsBit
Share
AI summary iconSummary
BTC update: The Coldcard attack remains active, with 1,367.05 BTC ($88.6 million) stolen from 4,585 addresses. Galaxy Research’s Alex Thorn urged users to move funds from compromised Coldcard addresses. He also called for sharing on-chain data to help track stolen assets and report incidents to authorities. Most BTC remains in the attacker’s wallets, but smaller actors are rapidly moving funds, with some flowing to offshore gambling platforms via ThorChain. Coldcard addresses created after the March 2021 firmware update are at risk. Security and education in self-custody remain critical.

According to Huoxing Finance, on August 2, Coldcard was compromised, with stolen funds rising to 1,367.05 BTC, valued at approximately $88.6 million, affecting 4,585 addresses. Galaxy Research Director Alex Thorn stated that the attack is still ongoing and users who have not yet migrated their funds should immediately transfer assets out of addresses generated by Coldcard. He also urged affected users to proactively provide information to assist in tracking the stolen funds and reporting to law enforcement. Thorn noted that the three previously confirmed large-scale attacks exhibited clear programmatic characteristics, with similar transaction patterns likely orchestrated through automation; the stolen BTC remains in the attackers’ addresses and has not yet been moved. However, recently, smaller opportunistic attackers have emerged, transferring and laundering funds within hours, with some funds routed through cross-chain services like ThorChain to overseas gambling platforms. All single-signature Coldcard addresses generated after the firmware update in March 2021 may ultimately be compromised, and users should migrate their assets as soon as possible. Previously, stolen funds remained dormant for an average of 3.18 years, with a median of 3.55 years, primarily affecting long-term holders. Thorn stated that most of the identified stolen assets have not yet been moved, and the relevant addresses have been submitted to U.S. law enforcement and industry contacts. He emphasized that this incident represents a significant blow to Bitcoin self-custody and called for the industry to improve security measures, user education, and risk awareness regarding the complexities of self-custody.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.