Key Highlights
- Galaxy Research says the Coldcard hack has grown to $75.1 million, with 1,158.66 BTC stolen in two waves and the funds still sitting untouched.
- Researchers linked both waves to the same Coldcard firmware flaw, warning that more attackers could target vulnerable wallets now that the weakness is public.
- Chainalysis found the hacker targeted the biggest wallets first, helping steal over $38 million from about 500 wallets in just 25 minutes.
Galaxy Research, a blockchain research firm, has reported that the recent Coldcard wallet attack is much bigger than first believed, with the total amount of stolen Bitcoin now reaching 1,158.66 BTC, worth about $75.1 million.
In a detailed X post on Saturday, the firm said more Bitcoin wallets were affected than originally reported, while the stolen funds remain untouched in wallets controlled by the attacker.
Stolen Bitcoin remains untouched
Galaxy Research said it is tracking seven Bitcoin addresses holding the stolen funds. So far, none of the Bitcoin has been moved, which the company described as unusual for a theft of this size.
According to the researchers, the attacker could be waiting for public attention to fade or may not yet have a safe way to move such a large amount of Bitcoin without attracting notice.
“The proceeds have not moved. All 1,158.66 BTC remains unspent across the attacker addresses, which is unusual for a theft of this size and suggests the operator is either waiting out scrutiny or lacks a laundering path for a sum this visible,” Galaxy Research said.
New findings point to the firmware flaw
As the investigation continued, researchers found another key clue. They discovered that every Bitcoin stolen in both waves was created after March 17, 2021, the date when the vulnerable Coldcard firmware was released. The oldest stolen coins in both attacks were all linked to wallets created after that software became available.
Galaxy Research said this is another strong sign that the thefts are connected to the same weakness in the wallet’s seed generation process. The firm added that it identified the attacker by studying transaction patterns on the blockchain, a method known as transaction fingerprinting. Much of that work was carried out by engineers at Block.
Galaxy also warned that this may not be the only person trying to exploit the flaw. Now that details of the vulnerability are public, other attackers could begin targeting wallets created with the same weak firmware.
Because of that risk, the firm urged affected users to act quickly. It said anyone using a single-signature Coldcard-generated seed, particularly one created without sufficient additional randomness or a strong BIP-39 passphrase, should move their Bitcoin to a new wallet generated with a fresh recovery seed.
Chainalysis explains how the attack happened
A day ago, blockchain analytics firm Chainalysis said the hacker did not steal Bitcoin randomly but carefully targeted the largest wallets first.
According to the firm, the approach allowed the attacker to collect more than $30 million within the first 10 minutes of the attack. In about 25 minutes, nearly 594 BTC, worth more than $38 million at the time, had been taken from around 500 single-signature Bitcoin wallets. Chainalysis also found that one victim alone lost about $1.8 million.
Coldcard bug opened the door for the theft
The attack was later linked to a software flaw in certain Coldcard Mk3 hardware wallets made by Canadian company Coinkite. The company said some firmware versions released between March 2021 and version 5.0.3 did not generate recovery seeds with enough randomness.
As a result, some seed phrases became significantly easier for attackers to guess using powerful computing resources.
Although Coinkite has released a software fix, it warned that simply updating the firmware is not enough. Users whose recovery seeds were created with the vulnerable software must generate an entirely new seed on updated hardware because old seeds remain at risk.
Also Read: Bitcoin Price Watch: Lower $60,000s Range Holds Amid Security Concerns
