Coldcard Hacker Moves $7.7M in Third-Wave Theft

iconNS3
Share
AI summary iconSummary
BTC news today reveals the Coldcard hacker moved 97.09 BTC, worth about $7.7 million, from the third theft wave. The funds were sent into CoinJoin rounds to hide the trail, and 20.5 BTC was swapped to ETH via THORChain. Galaxy Research says 82% of the stolen BTC remains unspent. The theft came from a firmware flaw introduced in March 2021. Coinkite has released updated firmware to fix the issue.

The Coldcard attacker moved 97.09 BTC from the third wave of thefts. The moved Bitcoin was worth about $7.7 million at Monday's prices. The amount represented roughly 45% of that wave's haul. Across the entire exploit, 82% of the stolen Bitcoin has not moved. The first exit came on September 2. About 20.5 BTC from the largest vault went through THORChain and emerged as Ethereum. The Bitcoin moved on Sunday night went into CoinJoin rounds. CoinJoin pools transactions from multiple users to break the trail between inputs and outputs. Only 20.56 BTC reached Ethereum. Another 57.24 BTC remains unspent as CoinJoin change in one address. Galaxy Research said the trail ends on roughly 19 BTC more. Galaxy said the attacker built 293 two-of-two multisig addresses. The attacker has been working through the addresses in order of size. Eleven addresses are now empty. The next ten addresses hold 30.81 BTC. The 233 smallest addresses hold 33.77 BTC. The thefts trace to a firmware bug that Coinkite introduced in March 2021. The bug moved seed generation from the device's hardware random-number chip to a software substitute. The change reduced key strength from 128 bits of entropy to as low as 40 bits. Attackers could then reconstruct private keys offline. They could drain single-signature addresses without touching the hardware. The sweeps began on July 30. Coinkite overhauled the firmware. The updated versions are Mk4/Mk5 5.6.2 and Q 1.5.2Q. The new process requires owners to provide randomness through key presses, dice rolls or coin flips. An update cannot repair a seed generated under the flawed version. Owners of wallets created on affected firmware must generate a fresh seed and move their coins to it. Coinkite chief executive Rodolfo Novak apologized in an open letter on July 31. Novak wrote that the company would have to earn back users' trust. A full technical postmortem is still in preparation. A previously unknown vault was fed by 58 addresses. Galaxy left the vault's cause open but believes it was another Coldcard victim. That finding would raise Galaxy's published exploit total to about 1,806 BTC. The published total would equal $143.9 million. Galaxy said in August that it was also carrying an unconfirmed fourth wave of 638.5 BTC. That wave would take the total past 2,400 BTC. Galaxy had logged no attacker sweeps since August 6.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.