Coldcard Exploiter Moves 45% of Stolen Funds Amid Ongoing Attacks
The Coldcard exploiter has moved about 45% of the assets stolen during Wave 3, according to Galaxy Research. This totals around $7.8 million in Bitcoin.
Galaxy estimates that 82% of all stolen Coldcard funds remain in attacker-controlled addresses, while the rest have been moved through transactions linked to laundering activity.
The attacks began on July 30 and were linked to a firmware bug that Coinkite shipped in 2021. The flaw affected how some Coldcard devices generated wallet seeds, making it easier for attackers to drain single-signature wallet addresses without gaining physical access to the hardware device.
Galaxy's research suggests that the Coldcard exploiter is moving funds from the largest vaults first, with wallets ranked from 1 to 11 already being drained. The total loss estimate could rise to around $143.9 million if a newly identified vault is confirmed to be linked to additional Coldcard victims.