4 hours ago

Coldcard hacker moves $7.7M, nearly half of third-wave haul

Coldcard Hacker Moves $7.7M, Nearly Half of Third-Wave Bitcoin Haul

Decrypt

The Coldcard attacker moved 97.09 BTC from the third wave of thefts. The moved Bitcoin was worth about $7.7 million at Monday's prices. The amount represented roughly 45% of that wave's haul. Across the entire exploit, 82% of the stolen Bitcoin has not moved. The first exit came on September 2. About 20.5 BTC from the largest vault went through THORChain and emerged as Ethereum. The Bitcoin moved on Sunday night went into CoinJoin rounds. CoinJoin pools transactions from multiple users to break the trail between inputs and outputs. Only 20.56 BTC reached Ethereum. Another 57.24 BTC remains unspent as CoinJoin change in one address. Galaxy Research said the trail ends on roughly 19 BTC more. Galaxy said the attacker built 293 two-of-two multisig addresses. The attacker has been working through the addresses in order of size. Eleven addresses are now empty. The next ten addresses hold 30.81 BTC. The 233 smallest addresses hold 33.77 BTC. The thefts trace to a firmware bug that Coinkite introduced in March 2021. The bug moved seed generation from the device's hardware random-number chip to a software substitute. The change reduced key strength from 128 bits of entropy to as low as 40 bits. Attackers could then reconstruct private keys offline. They could drain single-signature addresses without touching the hardware. The sweeps began on July 30. Coinkite overhauled the firmware. The updated versions are Mk4/Mk5 5.6.2 and Q 1.5.2Q. The new process requires owners to provide randomness through key presses, dice rolls or coin flips. An update cannot repair a seed generated under the flawed version. Owners of wallets created on affected firmware must generate a fresh seed and move their coins to it. Coinkite chief executive Rodolfo Novak apologized in an open letter on July 31. Novak wrote that the company would have to earn back users' trust. A full technical postmortem is still in preparation. A previously unknown vault was fed by 58 addresses. Galaxy left the vault's cause open but believes it was another Coldcard victim. That finding would raise Galaxy's published exploit total to about 1,806 BTC. The published total would equal $143.9 million. Galaxy said in August that it was also carrying an unconfirmed fourth wave of 638.5 BTC. That wave would take the total past 2,400 BTC. Galaxy had logged no attacker sweeps since August 6.

This content is an AI-generated summary/analysis for informational purposes only and does not constitute investment advice.