Crypto Today - Blockchain News / Bitcion

Header
Crypto Today - Blockchain News / Bitcion
collapse
BTC $78,585.00 -0.73% ETH $2,490.61 -0.17% SOL $103.89 -0.24% BNB $752.73 +1.61% XRP $1.43 +2.40% DOGE $0.0903 +0.14% ADA $0.2248 +1.55% LINK $12.68 -2.15% TRX $0.3391 +1.55% AVAX $8.01 -1.69%
Home / More News / Coldcard Hacker Moves 45% of Bitcoin Stolen in Third Attack Wave

Coldcard Hacker Moves 45% of Bitcoin Stolen in Third Attack Wave

  Crypto Today
Coldcard Hacker Moves 45% of Bitcoin Stolen in Third Attack Wave

The operator behind the third wave of the Coldcard thefts moved 97.09 BTC between September 2 and September 6, routing funds through THORChain and CoinJoin transactions. The transfers account for about 45% of the Bitcoin taken in that wave, according to CoinDesk.

The activity marks a concentrated effort to move a sizeable portion of the Wave 3 proceeds. Yet the broader estimated Coldcard haul remains largely parked in original attacker-controlled addresses, based on Galaxy Research’s tracking.

THORChain and CoinJoin received 97.09 BTC from Wave 3

On September 2, the Wave 3 operator transferred about 20.5 BTC through THORChain into Ethereum. Three days later, 15.48 BTC entered CoinJoin transactions, followed on September 6 by a further 61.12 BTC drawn from 10 additional vaults.

Together, those transactions totalled 97.09 BTC. The sequence used two distinct routes: a cross-chain transfer into Ethereum through THORChain and privacy-focused CoinJoin transactions on Bitcoin.

CoinJoin combines inputs from multiple users into joint transactions, making on-chain tracing more difficult than following a straightforward wallet-to-wallet transfer. The available reporting identifies the destinations and amounts, but does not establish what the operator intended to do with the transferred funds after the movements.

Eleven of 293 Wave 3 vaults supplied the moved bitcoin

The funds did not come evenly from the addresses linked to the third attack wave. The Block, citing Galaxy Research, reported that the attacker emptied the 11 largest of 293 Wave 3 vaults.

That leaves a substantially smaller balance in the next tier of wallets. The next 10 vaults held 30.81 BTC, while wallets ranked 61 through 293 held a combined 33.77 BTC, according to the research.

The pattern means nearly half of the wave’s stolen Bitcoin was mobilised from a narrow set of the biggest vaults rather than through a broad sweep of hundreds of addresses. It also leaves a long tail of smaller Wave 3 holdings that, collectively, contain limited balances relative to the emptied wallets.

Galaxy Research chart showing cumulative BTC stolen during the Coldcard attack waves. — Source: Galaxy Research

Most of the estimated 1,806 BTC Coldcard haul remains at original addresses

Galaxy’s broader estimate puts the Coldcard theft at roughly 1,806 BTC, valued at $143.9 million. The figure includes a previously unidentified vault that was funded by 58 addresses, and the firm estimated that about 82% of the stolen Bitcoin remained in original attacker-controlled addresses.

The Wave 3 transactions therefore mark a meaningful movement within one attack tranche, not a wholesale dispersal of the overall proceeds. The estimate is also higher than Galaxy’s August 14 confirmed count of 1,778.84 BTC stolen from more than 8,600 addresses and 190 victims.

At that point, Galaxy said 1,531 BTC had not moved and approximately 246 BTC had moved. About 65% of the moved funds had entered CoinJoin transactions, indicating that CoinJoin was already the principal route used for Bitcoin that had left its original addresses.

The new transfers reinforce that pattern. They also show that, despite the recent activity, the bulk of the estimated theft remains visible at the addresses initially controlled by the attacker.

A 2021 seed-generation flaw enabled offline key recovery

The thefts trace back to a seed-generation flaw introduced during a March 17, 2021 firmware change, according to Coinkite, the maker of Coldcard hardware wallets. The company said affected devices generated weakened seeds, allowing attackers to regenerate the corresponding private keys offline.

The incident therefore concerns seeds already generated under the affected conditions—not an online compromise requiring access to a device at the time of theft—and Coinkite said later firmware updates cannot repair those vulnerable seeds.

Galaxy’s August research placed the confirmed victim count at 190, while the subsequent estimate incorporated the previously unidentified vault. With 82% of the estimated 1,806 BTC still in original attacker-controlled addresses, the on-chain footprint of the Coldcard theft remains substantial even after the Wave 3 transfers.

Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

Source: Crypto Daily


  Crypto Today