Coldcard hacker withdraws 97 BTC, worth $7.7 million, in an Ethereum transaction

icon币界网
Share
AI summary iconSummary
Today’s BTC news reveals new on-chain activity from the Coldcard hacker, who recently moved 97.09 BTC—valued at $7.7 million—accounting for 45% of the third batch of stolen funds. The hacker split the funds: 20.5 BTC was swapped to Ethereum via THORChain, while 57.24 BTC entered a CoinJoin round. Galaxy Research found that 20.56 BTC reached Ethereum, and 33.77 BTC is held in smaller addresses. The vulnerability stemmed from a 2021 firmware flaw in Coinkite’s devices. Researchers also identified a new vault address potentially holding 58 BTC, which could bring the total stolen amount to 1,806 BTC.
CoinDesk reports:

Galaxy Research disclosed that recently, there has been on-chain activity involving the third wave of stolen funds from the Coldcard hardware wallet. Researchers noted that the attacker has transferred 97.09 BTC, equivalent to approximately $7.7 million at Monday’s price, accounting for about 45% of the total stolen in the third wave.

Funds are transferred in two directions.

On September 2, the attacker first transferred approximately 20.5 BTC from the largest vault address, then swapped them for Ethereum via THORChain. By the weekend, another batch of funds entered a CoinJoin round to obscure the correlation between transaction inputs and outputs.

Galaxy Research stated that the final amount of Bitcoin that reached Ethereum was 20.56 BTC. An additional 57.24 BTC remain at a single address as CoinJoin change, and researchers lost track of approximately another 19 BTC along subsequent paths.

293 addresses processed by size

Researchers stated that during the third wave of attacks, the attackers established 293 2-of-2 multisig vault addresses for victims' funds, processing them in descending order of size. So far, 11 of these addresses have been emptied.

  • The next 10 addresses collectively hold 30.81 BTC.
  • The remaining 233 smaller addresses collectively hold 33.77 BTC.
  • Approximately 82% of the stolen bitcoins remain unmoved throughout the incident.

The vulnerability dates back to the 2021 firmware.

This theft can be traced to a firmware flaw introduced by Coinkite in March 2021. The flaw moved the seed generation process from the device’s hardware random number chip to a software alternative, reducing key entropy from 128 bits to as low as approximately 40 bits.

Researchers say this allows attackers to offline reconstruct private keys and drain funds from single-signature addresses without needing access to the hardware device. Coinkite has since updated its firmware, but seeds generated under older versions cannot be fixed by upgrading alone; affected users must generate new seeds and transfer their assets.

Total scale may continue to be revised upward

Galaxy Research also mentioned a previously unreported treasury address funded by 58 addresses. Researchers have not yet confirmed its origin but believe it may also contain funds from Coldcard victims.

If this assessment is correct, the total stolen amount publicly recorded by Galaxy Research would rise to approximately 1,806 bitcoins, equivalent to about $143.9 million at the price cited in the article. The firm previously mentioned an unconfirmed fourth wave of funds amounting to 638.5 bitcoins; if verified, the total scale of the incident would exceed 2,400 bitcoins.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.