Clear, fast crypto news
BrefCryptoCrypto · Bitcoin · Africa
Menu
Bitcoin

Bitcoin: 45% of BTC stolen in Coldcard wave 3 moved

The attacker behind Coldcard’s third wave moved 45% of the stolen BTC, or 97.09 BTC, via THORChain and CoinJoin, according to Galaxy Research.

Bitcoins leaving compromised hardware vaults through mixed transaction routes
The attacker behind Coldcard’s third wave moved 97.09 BTC via THORChain and then CoinJoin transactions.

The attacker linked to the third wave of thefts targeting Coldcard hardware wallets has moved around 45% of the bitcoins stolen in this sequence, according to Galaxy Research. In total, 97.09 BTC, worth approximately $7.8 million, have already left the vaults tracked by researchers via THORChain and then CoinJoin transactions. Across the entire Coldcard incident, around 82% of the identified BTC remain on addresses controlled by the attackers.

The hacker starts with the largest vaults

Galaxy Research had already identified 293 2-of-2 multisignature vaults created as part of the third wave. The attacker now appears to be emptying them methodically, starting with the largest. The 11 biggest have already been moved.

This new stage extends the Coldcard incident that Bref Crypto was already following in August, when thousands of older bitcoins began changing addresses after the vulnerability was discovered.

The next-largest vaults still contain around 30.81 BTC, while the smaller ones, ranked from 61 to 293 by Galaxy, hold a total of 33.77 BTC. The third wave is therefore far from empty.

On-chain monitoring also identified a previously unknown vault consolidating funds from 58 addresses. Galaxy believes it could belong to another Coldcard victim, although it cannot yet confirm the exact source of the loss.

If this new batch is ultimately included in the calculation, the total attributed to the incident could reach approximately 1,806 BTC, or nearly $144 million at current prices.

THORChain followed by CoinJoin now complicates tracking

The first major movement took place on September 2. Around 20.5 BTC were sent to THORChain, a protocol that enables assets to be exchanged directly across different blockchains. Some of the bitcoins were therefore converted into Ether and then sent to new Ethereum addresses.

The subsequent movements used a different method.

On September 5 and 6, the attacker began using CoinJoin, a technique that combines transactions from multiple participants to make it more difficult to identify the exact origin and destination of the funds.

CoinJoin is not, in itself, a criminal tool. It is also used to improve Bitcoin users’ privacy. In this specific case, however, Galaxy considers these movements an attempt to obscure the traceability of the stolen funds.

This difficulty is well known to investigators. Malware targeting crypto wallets and accounts often first seeks to obtain credentials or keys, after which attackers make multiple transfers across protocols to complicate tracking.

Bitcoin nevertheless has one distinctive feature: every movement remains publicly visible. The identity behind an address may be unknown, but the transaction is not.

The vulnerability still affects the seeds, not Bitcoin

The technical point remains essential: Bitcoin itself was not compromised.

In its official security update, Coinkite explains that the incident resulted from a firmware bug introduced into Coldcard’s seed-generation process. Some devices produced recovery phrases with less entropy, and therefore less randomness, than expected. The attackers were then able to reconstruct certain private keys offline, without physically hacking the devices.

The distinction may seem technical, but it changes everything. A sufficiently random seed is supposed to provide such a vast search space that a brute-force attack becomes unrealistic. Reducing that entropy mechanically reduces the number of combinations that must be tested.

Coinkite now recommends firmware versions 5.6.2 for Mk4/Mk5 and 1.5.2Q for Q as the standard releases. However, the company stresses one point: updating the firmware does not repair an already-created vulnerable seed. Affected users must generate a new seed and transfer the funds to it.

This lesson extends beyond Coldcard. BitBox also recently had to fix two severe vulnerabilities in its hardware wallets. BTCPay Server, for its part, offered up to 3 BTC to recover stolen funds after another vulnerability.

Self-custody eliminates the risk of an exchange going bankrupt or arbitrarily freezing withdrawals. It does, however, shift responsibility to the software, hardware and quality of the keys used.

Coldcard now offers a costly demonstration of this principle: Bitcoin’s rules held, but the tool responsible for generating some of the keys did not meet the same standard.

À propos de l’auteur

Lydie Musekwa

Lydie Musekwa

Lydie Musekwa, enseignante chercheuse passionnée par les nouvelles technologies, plonge dans l'univers des cryptomonnaies avec un regard analytique et innovant. Depuis sa découverte du bitcoin, son parcours s'est orienté vers une exploration exhaustive de la blockchain et de ses applications. Armée d'un esprit critique et d'une soif d'apprendre, elle s'attache à démystifier les concepts technologiques complexes pour ses lecteurs, tout en scrutant les dernières tendances et avancées. En tant que rédactrice, Lydie s'engage à partager des connaissances précises et à jour, faisant le pont entre le monde académique et la sphère digitale en constante évolution.