Coldcard Wallet Exploit: Stolen Bitcoin Now Being Laundered as Attacker Cashes Out
Researchers at Galaxy Research report that the threat actor behind the third wave of attacks on Coldcard hardware wallets has now moved 45% of the coins stolen in that wave, transferring funds either to Ethereum via THORChain or into CoinJoin rounds designed to obscure the money trail. The attacker created 293 multisig vaults from victims' coins and has been systematically cashing out the largest holdings first, according to the research.
The underlying issue stems from a firmware flaw introduced in a March 2021 update. A build error caused affected wallets to use a weak software random number generator instead of their intended hardware-based source, reducing seed security from an expected 128 bits down to as little as 40 bits on older devices. This weakness allowed attackers to brute-force wallet keys without ever needing physical access to the device.
Across all attack waves, roughly 82% of stolen funds remain untouched in attacker-controlled addresses, while the remaining 18% is being actively laundered. The exploit triggered a surge in Bitcoin network activity as affected users rushed to move and consolidate holdings, though it had little visible effect on Bitcoin's price.
Key Takeaway: Businesses using hardware wallets or crypto custody devices should ensure firmware is kept fully up to date and verify vendor security advisories, since even trusted hardware can carry years-old flaws that undermine key generation.