Coldcard Exploit Steals $111M in Bitcoin, 25+ Attack Patterns Identified

iconAMBCrypto
Share
AI summary iconSummary
Bitcoin news broke as investigators confirmed a $111 million theft via the Coldcard exploit, with 1,719 BTC stolen. Galaxy Research estimates losses could top $130 million if unconfirmed cases are verified. The flaw affected Coldcard wallets with firmware updates after March 17, 2021, enabling remote access. Over 25 attack patterns were found across three waves, impacting Mk3, Mk4, Mk5, and Q models. More than 250 victims have reported losses, though the true number may be higher. Bitcoin analysis suggests the breach highlights ongoing risks in hardware wallet security.

The Colcard exploit appears to be much larger than first thought. This is because investigators have now confirmed that at least 1,719 Bitcoin [BTC], or about $111 million, has been stolen from victims of the Coldcard exploit.

losses likely exceed $130m
Source: Galaxy Research

In fact, according to Galaxy Research,

We have many more coins we are vetting for confirmation – we think total losses likely exceed $130m.

AD

So, if the suspicious but unconfirmed cases on their current list turn out to be confirmed, the total might surpass 2,300 Bitcoin.

total loss to 2300+ BTC
Source: Galaxy Research

How did this attack take place in the first place?

For context, the incident involved a flaw in some Coldcard wallets using firmware released after 17th March 2021. The flaw may have affected wallet-seed security or generation.

Since the seed served as a Bitcoin [BTC] wallet’s master key, attackers who managed to recreate it were able to access the money without the Coldcard being physically compromised.

Not one stolen coin was created onchain
Source: Galaxy Research

The firmware release date mattered because investigators found no stolen coins from wallets created before then. They identified over 25 attack patterns across three waves. This suggested multiple threat actors exploited the vulnerability.

25 separate attack patterns
Source: Galaxy Research

How widespread was the Coldcard exploit?

So far, over 250 victims have reported losses. However, the number of affected addresses may be much higher. A single victim could have used several wallets.

Galaxy Research said that not every Coldcard wallet faced exposure. However, Mk3, Mk4, Mk5, and Q models appeared vulnerable. Those models ran firmware released after 17th March 2021.

For context, the Coldcard exploit started on 30th July.

An attacker drained approximately 594 BTC, worth $38 million, from 500 wallets within 15 to 25 minutes.

The attack created concern across the Bitcoin community. Even so, Bitcoin’s core network remained unaffected.


Final Summary

  • Galaxy Research has discovered over 25 attack patterns in three waves.
  • If the current list turns out to be confirmed, the total losses might surpass 2,300 Bitcoin.
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.