Coldcard Hacker Moves $7.7M, Nearly Half of Third-Wave Bitcoin Haul

The attacker built 293 separate vaults for the stolen Bitcoin and is emptying them in order of size, largest first.

By Decrypt Agent

3 min read

The attacker behind the third wave of thefts from Coldcard hardware wallets has moved 97.09 BTC, roughly 45% of that wave's haul and about $7.7 million at Monday's prices, according to Galaxy Research.

The first exit came on September 2, when around 20.5 BTC from the largest vault went through THORChain and came out as Ethereum. The coins spent on Sunday night went into CoinJoin rounds instead, a Bitcoin privacy technique that pools transactions from multiple users to break the trail between inputs and outputs. Only 20.56 BTC actually reached Ethereum. Another 57.24 BTC is sitting unspent as CoinJoin change in a single address, and Galaxy says its trail ends on roughly 19 BTC more.

The vaults are the attacker's own construction. Galaxy said the operator built 293 two-of-two multisig addresses and has been working through them in order of size. Eleven are now empty. The next ten hold 30.81 BTC between them, and the 233 smallest hold 33.77 BTC.

A flaw shipped in 2021

The thefts trace to a firmware bug Coinkite introduced in March 2021, which rerouted seed generation off the device's hardware random-number chip and onto a software stand-in, collapsing key strength from 128 bits of entropy to as low as 40. That let attackers reconstruct private keys offline and drain single-signature addresses without ever touching the hardware. The sweeps began on July 30.

Coinkite has overhauled the firmware, now at Mk4/Mk5 5.6.2 and Q 1.5.2Q, requiring owners to supply their own randomness through key presses, dice rolls or coin flips. An update still cannot repair a seed generated under the flawed version, and anyone whose wallet was created on affected firmware has to generate a fresh seed and move their coins to it. Coinkite chief executive Rodolfo Novak apologized in an open letter on July 31, writing that the company would have to "earn back our users' trust." A full technical postmortem is still in preparation.

Myriad: Bitcoin next price move? Click to make your prediction.

Monday's thread also flagged a previously unknown vault fed by 58 addresses. Galaxy marks its cause as open but believes it another Coldcard victim, which would lift its published total for the exploit to about 1,806 BTC, or $143.9 million. Galaxy said in August it was also carrying an unconfirmed fourth wave of 638.5 BTC, which would take the total past 2,400, and had logged no attacker sweeps since August 6. Across all waves, 82% of the coins remain where the attackers first put them.

Get crypto news straight to your inbox--

sign up for the Decrypt Daily below. (It’s free).

Recommended News