Coldcard Exploit Leaves Stolen Bitcoin Under Watchful Eyes
Over $100 million in Bitcoin has been stolen through an ongoing exploit of the Coldcard wallet, but according to market commentator Joe Consorti, the thief may struggle to spend most of it due to the transparency of the blockchain.
Coldcard's device firmware released after March 2021 was found to have a weakness that allowed attackers to generate weak seed phrases, compromising private keys and leaving users vulnerable. The incident has highlighted an often-overlooked feature of Bitcoin: while private keys can be compromised, the movement of stolen units remains visible on the public blockchain.
Galaxy Research has identified 1,596 BTC stolen across roughly 7,300 addresses in three confirmed attack waves, with around 90% of the stolen coins remaining unmoved. The firm has shared all the confirmed attacker addresses with US law enforcement agencies and crypto exchanges to aid in tracking the stolen funds.
Consorti argued that Bitcoin's transparency makes it a challenging asset for crime, noting 'Bitcoin might be the worst money for crime ever invented.' He also emphasized that the exploit was not a failure of the Bitcoin network but rather of wallet software. Coinkite, the company behind Coldcard, has patched newer firmware and advised users to move their funds to unaffected hardware.