The incident showed that large-scale losses can continue due to a firmware-stage randomness vulnerability without directly stealing the hardware wallet itself. [Photo: Shutterstock]

In a series of thefts targeting Coldcard bitcoin wallets, about 45 percent of the funds taken in a third attack has already been moved. As the attacker continues shifting stolen funds using coinjoin and cross-chain transactions, the overall losses are also growing beyond earlier estimates.

Galaxy Research cited by blockchain media outlet Decrypt on Sunday said 97.09 BTC from the third theft has been moved so far. It was worth about $7.8 million at the time, it added.

Recent fund movements have shown a pattern aimed at making stolen bitcoin harder to trace. Galaxy said the attacker carried out a CoinJoin transaction on Sunday and earlier on Sept. 2 used THORChain to swap stolen bitcoin into ether. Based on this, Galaxy assessed that the attacker is trying to launder the stolen cryptocurrency by moving it continuously.

The attacker’s fund-moving pattern has also been identified. Galaxy’s tracking showed the attacker is moving funds starting with wallets holding the largest amounts, followed by wallets with relatively smaller balances.

Funds in wallets ranked 1 through 11 have already been moved, it found. The next 10 wallets that the attacker has not yet touched still hold a combined 30.81 BTC, while smaller wallets ranked 61 through 293 hold a dispersed 33.77 BTC.

The possibility of further increases in losses has also been raised. During its tracking, Galaxy discovered a new, unidentified cluster of storage wallets consisting of 58 addresses and judged it highly likely those addresses could be linked to Coldcard victims. If those addresses are included, the bitcoin stolen in the Coldcard attacks rises to 1,806 BTC, worth about $143.9 million at current prices.

Not all of the stolen bitcoin has moved to the attacker’s external wallets. Based on the overall scale of the attacks, about 82 percent of the funds is still in the existing addresses controlled by the attacker, Galaxy assessed.

Galaxy believes a significant portion of the amount already moved was transferred not as a simple wallet shift but for laundering purposes. If the remaining bitcoin is moved further, the actual scale of losses and the laundering routes could become clearer.

The series of thefts first began on July 30. The cause identified was a defect in firmware distributed in 2021 by Coldcard maker Coinkite. The defect is known to have weakened the randomness used when Coldcard generates wallet seed phrases. Using the vulnerability, the attacker could estimate individual seed phrases through brute force and steal bitcoin stored in single-signature addresses without accessing the physical device.

The scale of losses rose quickly after the incident. Galaxy identified that about 1,779 BTC had been taken by mid-August from 190 victims and more than 8,600 addresses.

With the newly linked cluster of 58 addresses included, the total stolen amount expanded to about 1,806 BTC. While the possibility of further attacks has been raised, Galaxy has not yet been able to confirm that a fourth theft has occurred.

The key variable in the case is whether the remaining stolen funds move further. With a substantial amount of bitcoin still in existing addresses and a new cluster of victim addresses discovered, the incident is expanding beyond a single wallet hack into a prolonged series of thefts.

Keyword

#Coldcard #Bitcoin #Galaxy Research #THORChain #CoinJoin
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.