Coldcard Wallet Hack: Attacker Launders Nearly Half of Latest Stolen Bitcoin
An attacker exploiting a firmware flaw in Coinkite's Coldcard hardware wallets has moved nearly half the Bitcoin stolen in the third wave of a broader campaign, according to Galaxy Research. The attacker has spent 97.09 BTC (about $7.8 million) from this wave, partly by swapping funds into Ether through THORChain and, more recently, by routing Bitcoin through CoinJoin transactions, a method that makes fund tracing more difficult.
The underlying vulnerability, introduced in 2021, weakened how Coldcard devices generated wallet seeds, allowing attackers to potentially brute-force seed phrases for affected single-signature wallets without ever touching the physical device. Attacks began on July 30, and by mid-August Galaxy had traced roughly 1,779 BTC stolen from 190 victims across more than 8,600 addresses. Galaxy now estimates about 82% of all stolen funds remain in attacker-controlled addresses, with the rest being laundered through various methods.
Galaxy's latest research also uncovered a previously unidentified group of 58 addresses believed to belong to additional Coldcard victims, which would push the total stolen to around 1,806 BTC (about $143.9 million). Researchers warn that a further attack wave, though unconfirmed, remains possible, suggesting the full scope of the incident is still unfolding.