Skip to content

Bringing you global stories from a neutral view

Cryptocurrency

Coldcard Wallet Hackers Move Stolen Bitcoin for First Time

Hackers behind the Coldcard wallet exploit have moved stolen Bitcoin into Ether for the first time, executing transactions worth $115 million.

Coldcard Wallet Hackers Move Stolen Bitcoin for First Time

Hackers who stole Bitcoin from Coldcard hardware wallets have begun converting the stolen assets into Ether, according to Galaxy head of research Alex Thorn. The transactions represent the first confirmed movement of funds from hacker addresses across all three waves of security breaches targeting the devices.

The unidentified individuals transferred approximately 20.5 BTC using the cross-chain protocol THORChain, with the converted funds arriving on the Ethereum blockchain network. THORChain is a decentralized liquidity protocol that enables users to swap native cryptocurrency assets between separate blockchain networks without using centralized financial intermediaries.

HRP97PUXQAAxWuU.jpeg

Thorn explained that the stolen coins moved through a collector wallet, a pay-to-witness-script-hash storage vault, and several two-of-two multisignature transactions before reaching THORChain. He noted that about 90 percent of the funds stolen during the third wave of attacks remain untouched, explaining that the attackers attempted to transfer funds several times previously, but those transactions were returned.

Sophisticated Multi-Signature Transfer Tactics

Thorn drew attention to the specific setup of the hacker wallets, noting that the perpetrators did not simply store the stolen funds in conventional addresses as is common in cryptocurrency thefts. Instead, the attackers intentionally implemented a two-of-two multisignature structure, creating digital storage that functions like a safe requiring two separate keys to open.

The attackers also created a new pair of cryptographic keys for every intermediate transfer made along the transaction chain. Thorn explained that this systematic key rotation complicates tracking efforts for investigators and gives the hackers tighter control over how the funds are withdrawn.

Millions Stolen Across Multiple Attack Waves

Confirmed total losses from the Coldcard vulnerability stand at approximately 1,789 BTC, worth about $115 million, according to estimates by digital asset firm Galaxy. The widespread exploit compromised more than 8,800 individual wallet addresses across what analysts believe were at least three distinct attack waves.

The third wave of breaches differed markedly from the earlier attacks. Rather than collecting all the stolen cryptocurrency into a single master account, the perpetrators distributed the funds across hundreds of separate individual accounts to evade easy detection.

Flaw Identified in Wallet Firmware Seed Generation

The initial attack occurred on July 30, uncovering a security flaw in the wallet software. Coldcard manufacturer Coinkite acknowledged that certain firmware versions released since March 2021 generated security seed phrases in a manner that was more predictable than initially designed. Seed phrases are secret sequences of words generated by wallets to back up and recover private cryptographic access keys.

Coinkite confirmed that the physical hardware devices themselves were not remotely breached over internet connections. Instead, the attackers were able to mathematically reconstruct the private cryptographic keys offline to gain unauthorized control of the wallet balances.

Related

Leave a comment

Your email address will not be published. Required fields are marked *