Coldcard Exploit Perpetrator Continues Laundering Stolen Bitcoin
The Coldcard exploit occurred over a month ago, but the attacker responsible has continued to move funds. In mid-September, Galaxy Research analyzed on-chain activity and found that the thief is using different transaction paths to launder the stolen Bitcoin. The laundering route first involved moving funds through THORChain into Ethereum, followed by Bitcoin CoinJoin transactions.
The attacker created 293 separate 2-of-2 multisig vaults, each corresponding to a victim or group of victim funds. Approximately 208.24 BTC was consolidated from around 1,912 victim addresses into these collection addresses. The funds were then distributed among the 293 vaults, creating a structured system for storing the stolen Bitcoin.
The attacker has been spending the vaults in order of their original BTC content. The first major exit occurred on September 2nd, when the largest vault's 20.50 BTC was routed through THORChain into Ethereum. Two Ethereum addresses receiving the funds have since been emptied.