Galaxy Reports Coldcard Wave 3 Hacker Moves 45% of Stolen Bitcoin

iconTheCryptoBasic
Share
AI summary iconSummary
Bitcoin breaking news: Galaxy Research reports the Coldcard Wave 3 hacker has moved 45% of the stolen Bitcoin, totaling 97.09 BTC or $7.8 million. The movement includes CoinJoin transactions and an Ethereum swap via THORChain. The hacker continues to launder the Bitcoin.

The attacker behind the third wave of Coldcard Bitcoin wallet thefts has moved 45% of the funds stolen in that phase, with 97.09 BTC worth $7.8 million at Monday’s prices spent so far, Galaxy Research said in its analysis.

In posts on social media platform X, Galaxy said the latest activity involved CoinJoin transactions on Sunday, following an earlier move on Sept. 2 in which the exploiter swapped stolen Bitcoin into Ethereum through THORChain. The research firm said the operator continues to move the stolen coins.

Coldcard Wave 3 Exploiter Moves 45% of Stolen Bitcoin
Coldcard Wave 3 Exploiter Moves 45% of Stolen Bitcoin

Exploiter Moves Largest Coldcard Theft Vaults First

Galaxy’s tracking shows the attacker has been moving the stolen holdings from the largest vaults to the smallest. Vaults ranked 1 through 11 have already been moved, while the next 10 untouched vaults contain a combined 30.81 BTC. Another 33.77 BTC is spread across the smaller vaults ranked 61 through 293.

Coldcard Wave 3 Exploiter Moves Largest Bitcoin Vaults First
Coldcard Wave 3 Exploiter Moves Largest Bitcoin Vaults First

In its Monday post, Galaxy also linked the operator to a previously unidentified vault comprising 58 addresses that the research firm said are likely associated with Coldcard victims. If those addresses are included, the amount stolen across the Coldcard attacks would rise to 1,806 BTC, equivalent to $143.9 million at current prices.

Across the overall exploit, 82% of the stolen funds remain in the original addresses controlled by the attackers. Galaxy said the remainder has been moved for laundering purposes.

Firmware Flaw Allowed Coldcard Seeds to Be Brute-Forced

The thefts began on July 30 and originated from a firmware bug that Coinkite shipped in 2021. The flaw reduced the randomness used when Coldcard devices generated wallet seeds, enabling attackers to brute-force private seed phrases and drain single-signature addresses without accessing the devices themselves.

By mid-August, Galaxy had identified roughly 1,779 BTC taken from 190 victims and more than 8,600 addresses. The research firm has also raised the possibility of a fourth wave of thefts, although it has not confirmed one.

DisClamier: This content is informational and should not be considered financial advice. The views expressed in this article may include the author's personal opinions and do not reflect The Crypto Basic opinion. Readers are encouraged to do thorough research before making any investment decisions. The Crypto Basic is not responsible for any financial losses.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.