Coldcard attacker moves 97 BTC worth about $7.7 million through Ethereum route

AI مارکیٹ کا خلاصہ
Reports of ongoing Coldcard-related theft activity show 97.09 BTC moved, including 20.56 BTC bridged into ETH via THORChain, with CoinJoin used to obscure flows and ~19 BTC becoming untraceable. The incident stems from a 2021 firmware entropy flaw and could expand the known stolen total to ~1,806 BTC (and potentially >2,400 BTC if a fourth wave is confirmed). This reinforces wallet-security and provenance risks, increasing near-term headline and compliance sensitivity for BTC flows.
اثر کی سطح
● درمیانہ
متاثرہ اثاثے
BTC/USDT-0.93%
AI تجزیاتی سمجھ · BTC/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
CoinDesk reports that Galaxy Research has identified fresh onchain movements tied to the third tranche of stolen funds linked to the Coldcard hardware wallet incident. Researchers say the attacker has moved 97.09 BTC—about $7.7 million at Monday's price—roughly 45% of the bitcoin taken in the third wave. Galaxy Research describes two main flows. On Sept. 2, the attacker sent about 20.5 BTC out of the largest vault address and swapped it into Ethereum via THORChain. By the weekend, another set of funds entered a CoinJoin round intended to break the link between transaction inputs and outputs. The firm said 20.56 BTC ultimately reached Ethereum. Another 57.24 BTC remains at a single address as CoinJoin change, while roughly 19 BTC could not be traced further along subsequent paths. According to the researchers, the third-wave operation involved 293 2-of-2 multisig vault addresses set up to hold victims' funds, with withdrawals processed from the largest balances downward. To date, 11 of these addresses have been emptied. The next 10 addresses together hold 30.81 BTC, and the remaining 233 smaller addresses hold a combined 33.77 BTC. Galaxy Research estimates about 82% of the stolen bitcoin has not moved since the incident. The underlying issue traces back to a Coinkite firmware change introduced in March 2021. Researchers say moving seed generation from the device's hardware random number chip to a software method reduced key entropy from 128 bits to as low as about 40 bits, enabling attackers to reconstruct private keys offline and drain funds from singlesignature addresses without physical access to the device. Coinkite has since updated its firmware, but seeds created under older versions cannot be remediated by upgrading alone; affected users must generate new seeds and move their assets. Galaxy Research also flagged a previously unreported treasury address funded by 58 addresses. Its origin has not been confirmed, but the firm believes it may also contain funds from Coldcard victims. If so, Galaxy Research's publicly recorded total would rise to about 1,806 BTC, or roughly $143.9 million at the price cited in the report. The firm has also referenced an unconfirmed fourth wave totaling 638.5 BTC; if verified, the incident's overall losses would exceed 2,400 BTC.