COLDCARD Seed Bug Exploit: 1,159 BTC Held, 64 BTC Sent to Mixer

iconChainGPT
Share
AI summary iconSummary
A major exploit of the COLDCARD seed-generation flaw has led to the theft of 1,159 BTC, still held in seven addresses. A separate actor sent 64 BTC to a mixer, with 10 BTC mixed and 54 BTC split for laundering. Galaxy Research linked 600 addresses to the theft, as law enforcement and exchanges track for CFT violations. The flaw allowed offline seed reproduction and on-chain address matching. Coinkite released corrected firmware, urging users to generate new seeds. Investigators are following mixer activity, as BTC as hedge against inflation remains a key focus in tracing illicit flows.

A major COLDCARD exploit continues to play out on-chain: the single largest attacker tied to the vulnerability is still holding 1,159 BTC across seven addresses, while a separate actor has begun routing smaller sums through a mixer — offering investigators a new trail to follow. What’s happening on-chain - Galaxy Research’s on-chain monitoring shows the largest known theft — 1,159 BTC — was swept into seven addresses within about 41 minutes and those balances have not been moved since. Investigators haven’t seen transfers from those addresses to exchanges, mixers, or typical cash-out services. - Technically the funds aren’t frozen — Bitcoin transactions can’t be stopped by the protocol simply because an address has been flagged — but moving those coins into fiat or regulated services would likely trigger AML/KYC controls. Law enforcement, exchanges and analytics firms have flagged roughly 600 addresses tied to the broader theft, increasing the risk that any deposit to a compliant platform would draw scrutiny. New mixer activity - Separately, analysts traced a 64 BTC flow into a mixer-linked transaction. Roughly 10 BTC was mixed immediately, while about 54 BTC returned as change and was split into roughly 7 BTC outputs for further mixing. - Mixers attempt to obscure provenance by recombining and reshaping transactions, but they don’t guarantee anonymity. In this case, the relatively large and uniform outputs make the laundering pattern easier to follow, meaning investigators can keep monitoring those hops. Multiple attackers, multiple clusters - The mixer activity appears unconnected to the seven-address cluster holding 1,159 BTC. Earlier reporting indicated multiple attackers may have exploited the same COLDCARD seed-generation flaw, so activity from one cluster shouldn’t be assumed to come from the same actor. - Galaxy Research previously confirmed about 1,596 BTC was stolen in three attack waves from roughly 7,300 addresses and identified 14 smaller related incidents. A suspected fourth wave could bring the total near 2,055 BTC, though that addition hasn’t been fully verified with victim reports. How the exploit worked and the fallout - The vulnerability stemmed from a firmware bug that weakened randomness when generating seed phrases. Attackers could reproduce candidate seeds offline, derive addresses, and match them with live addresses on-chain — without needing device access, PINs, or any protocol-level compromise. - Coinkite has released corrected firmware, but updating a device doesn’t fix a seed that was created with a vulnerable version. Affected users must generate a new seed and transfer funds to addresses derived from it to be secure. Enforcement and recovery prospects - Galaxy shared confirmed attacker and victim addresses with US law enforcement, exchanges and cyber-investigation groups. That broader address list improves the chance of detecting attempts to route coins through regulated rails. - Still, recovery is uncertain. Attackers can route funds through multiple addresses, mixers, decentralized platforms or jurisdictions outside US reach before attempting to cash out. Bottom line The largest known COLDCARD-related attacker is currently sitting on 1,159 BTC that hasn’t moved since the initial sweep, leaving those coins exposed to continuous public surveillance. Meanwhile, recent mixer activity by another actor has created a followable trail that investigators will be watching closely as the situation develops.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.