Galaxy Research reveals that funds stolen in the third wave from Coldcard hardware wallets have once again shown unusual activity on the blockchain recently. Researchers say that attackers have transferred out 97.09 bitcoins, which is approximately $7.7 million at Monday's prices, accounting for about 45% of the funds obtained in the third wave.
The funds are transferred in two routes.
On September 2nd, the attackers first transferred approximately 20.5 bitcoins from the largest vault address. After using THORChain for cross-chain conversion, they converted them into Ethereum. By the weekend, another batch of funds entered the CoinJoin round, which was used to disrupt the correspondence between transaction inputs and outputs.
Galaxy Research indicates that the actual amount of funds that ultimately reached Ethereum was 20.56 Bitcoins. Additionally, there are 57.24 Bitcoins remaining in a single address in the form of CoinJoin change. The tracking of the approximately 19 additional Bitcoins was interrupted at a later stage.
293 addresses are processed based on their size.
Researchers stated that during the third wave of attacks, the attackers established 293 2-of-2 multi-signature wallet addresses for the victims' funds, and processed them in descending order of address size. To date, 11 of these addresses have been emptied.
- The next 10 addresses collectively hold 30.81 Bitcoins.
- The remaining 233 smaller addresses hold a total of 33.77 Bitcoins.
- Approximately 82% of the stolen bitcoins in this entire incident have not yet been moved.
The vulnerability can be traced back to firmware from 2021.
This theft incident can be traced back to a firmware flaw introduced by Coinkite in March 2021. This flaw shifted the seed generation process from the device's hardware random number chip to a software-based alternative, resulting in a reduction in key entropy strength from 128 bits to a minimum of about 40 bits.
Researchers say this allows attackers to rebuild private keys offline and clear funds from short-positioned addresses without having to access the hardware device. The firmware has been updated since Coinkite, but seeds generated under the older versions cannot be directly repaired through an upgrade. Relevant users still need to generate new seeds and transfer their assets.
Total scale may continue to be revised upwards.
Galaxy Research This time, an undisclosed vault address was also mentioned, which was funded by 58 addresses. Researchers have not yet confirmed the cause of this, but they believe it may also belong to the funds affected by Coldcard.
If this judgment holds true, the total amount of bitcoins stolen, as publicly reported by Galaxy Research, will rise to approximately 1,806 bitcoins, which is worth about 143.9 million US dollars at the price mentioned in the text. The institution also previously mentioned a fourth wave of funds that has not yet been confirmed, involving 638.5 bitcoins. If confirmed, the total scale of the incident will exceed 2,400 bitcoins.









