USDT Issuer Tether Hits $1.5B Q2 Profit, Hoards 98,932 Bitcoin
Coldcard Attacker Stole $30M in 10 Minutes by Targeting Big Wallets
(Originally posted on : Bitcoin News )
Key Takeaways
- The attacker stole roughly $30 million during the first 10 minutes.
- Investigators identified 500 victim wallets swept within 25 minutes.
- Vulnerable seeds require replacement, even after installing the hotfix.
Attacker Prioritized Coldcard Wallets With the Largest Balances
Blockchain analytics firm Chainalysis revealed on July 31 that the attacker targeted high-value Coldcard hardware wallets early, rapidly increasing the total amount stolen. The firm found that three of the 10 largest affected wallets held at least 10 BTC, worth approximately $636,000 during the analysis.
One victim lost about $1.8 million, while the cumulative value taken climbed toward $30 million during the operation’s first 10 minutes. The ordering suggested that the attacker had examined the available wallet population before beginning the systematic sweep.
Chainalysis reported:
“This pattern suggests that the attacker studied the victim wallet population before proceeding.”
Over approximately 25 minutes, the attacker drained 500 distinct wallets, producing a sharp increase in stolen value before expanding across smaller balances. Chainalysis used its Reactor investigation platform to examine the flow of funds, victim addresses, and concentration among the largest losses.
The sequence indicates a deliberate effort to maximize early proceeds rather than processing wallets randomly or following their original generation order. Prioritizing larger balances also reduced the risk that warnings, exchange controls, or defensive transfers would limit the attacker’s most valuable opportunities.
Paid Blockchain Service Account Traced During Sweeps
Block’s investigation into the Coldcard wallet drains began after the company’s bitcoin engineering and security teams received reports that wallets outside the company’s Bitkey platform were being drained. Bitkey Engineering Lead Clay Garrett described an unusual request pattern that helped investigators identify a suspected operational workflow.
Investigators determined that the operator had used a paid account at a well-known blockchain-services provider to query source addresses and conduct related activity. The provider’s internal records reportedly matched the suspected number, timing, and sequence of requests with what Garrett characterized as extraordinary specificity.
Garrett stated:
“The provider was supplying its standard services in response to requests that did not reveal their broader purpose.”
Block found no evidence that the unnamed provider knowingly participated in the suspected theft or intentionally helped the operator carry it out. The company contacted the provider directly and began sharing relevant information with appropriate authorities while limiting disclosures that could disrupt the investigation.
Coinkite Advisory Identifies Affected Coldcard Firmware
As investigators traced the stolen funds, Coinkite reiterated which devices were affected by the underlying vulnerability. The company’s Coldcard Mk3 security advisory covered devices that generated seeds on firmware versions 4.0.1 through 5.0.3. Early findings indicated that Mk4, Q, and Mk5 models were unaffected, while reports linked roughly 594 BTC, valued at nearly $38 million, to about 500 dormant wallets swept within approximately 25 minutes.
Many affected addresses had remained inactive for years and commonly held balances ranging from 0.15 BTC to 0.26 BTC. Coinkite recommended creating a replacement seed on an unaffected device, sending a small test transaction, confirming the receiving address on the hardware screen, and retaining the previous backup until the migration succeeds.
Vulnerable Seeds Remain Exposed After Firmware Updates
Coldcard owners who generated seeds using vulnerable firmware face risks that installing the latest hotfix alone cannot resolve. Chainalysis advised affected users to create an entirely new seed on patched hardware before transferring their bitcoin from affected wallets.
The firm also recommended using a strong BIP-39 passphrase for additional protection. Chainalysis continues monitoring the exploiter wallet, a consolidation address, and reports of potentially ongoing attacks against addresses suspected to be derived from vulnerable private keys. Block said it will release additional findings once doing so no longer risks interfering with the investigation.