During the attack, the attackers withdrew 1,324 UTXOs (unspent transaction outputs, remaining bitcoins on wallets after certain transactions), according to Atlas21. The stolen coins have not yet been transferred to an exchange or a crypto mixer: 562 bitcoins are currently stored on a new address, and another 32 bitcoins are on an intermediate address.
Each of the attackers’ transactions emptied exactly one victim address. While 419 addresses had only one UTXO, some accumulated up to 105 or 200 UTXOs. The median loss per victim was 0.41 BTC (approximately $26,500); 110 victims lost more than 1 BTC, and the maximum loss reached 29.9 BTC (nearly $2 million). No victim lost less than 0.15 BTC—security experts believe the attackers filtered wallets by minimum balance.
The investigation into the incident began after one of the Reddit bloggers reported a cryptocurrency theft. According to the author, he purchased a Coldcard wallet in 2021; the 24-word seed phrase was generated directly on the device, funds were then sent to the wallet, followed by years of inactivity. In January last year, the Reddit user bought a second Coldcard and re-entered the old seed phrase “to verify that the words were correct.” The blogger claims he never shared the seed phrase with anyone and used it exclusively on the Coldcard.
Coinkite has acknowledged a security issue affecting seed phrases generated on Coldcard Mk3 devices. The manufacturer recommends that all users who created a seed phrase on an Mk3 device with firmware version 4.0.1, released in March 2021, or any later version, consider their funds compromised. The company stated that models Mk4, Q, and Mk5 are not affected by this issue.
Coinkite recommends that Mk3 owners generate a unique BIP-39 passphrase on the device and transfer funds to a new wallet. The company acknowledged that the cause of the vulnerability has not yet been identified. It is confirmed that none of the affected wallets are multisignature.
Blockchain analysts from Atlas21 suggest the issue is not with the hardware wallet itself, but with weak seed phrases. The affected users likely imported already compromised or easily guessable word combinations into their devices. Due to “insufficient randomness” in the generation of the seed phrases, private keys for individual UTXOs could be easily brute-forced, which attackers did, security experts explained.
Recently, Singapore-based company Triple-A, which provides businesses with infrastructure for payments in stablecoins and other cryptocurrencies, suffered a cyberattack. The damage is estimated at $11.8 million.

