WRITTEN IN PLAIN AMERICAN ENGLISH.
About
CLAY TRIBUNE.
ShopCartAccount
Advertisement

Coldcard Wave 3 Attacker Moves 97 BTC Worth $7.7 Million Through THORChain and CoinJoin

A fault within a wallet's design let a thief take millions in coin, moving nearly half of one holding while most remains where it was placed.

By mitch·3 min read
A broken chamber of metal and light pours forth its treasure of coin into the waiting dark.

The attacker behind the third wave of Coldcard thefts has moved 97.09 BTC, close to $7.7 million and about 45% of that wave’s total, Galaxy Research said Monday.

The First Move on September 2

The first coins left on September 2, when about 20.5 BTC from the largest holding went through THORChain and came out on the other side as Ethereum. Only 20.56 BTC actually arrived on Ethereum, Galaxy said. The rest of the weekend’s activity took a different path.

CoinJoin Rounds Over the Weekend

Coins spent Sunday night went into CoinJoin rounds instead, a Bitcoin privacy method that mixes transactions from many users together to make it hard to trace which coins came from where. Galaxy said 57.24 BTC now sits as CoinJoin change in a single address, not yet spent. The record on roughly 19 BTC more simply ends, according to Galaxy.

Advertisement

How the Addresses Were Made

The holdings belong to the attacker’s own design. Galaxy said the operator made 293 addresses, each requiring two separate keys to move funds, for wave 3, and has been working through them by size, largest first.

  • Eleven addresses are now empty.
  • The next ten hold 30.81 BTC between them.
  • The 233 smallest hold 33.77 BTC combined.

Where the Bug Came From

The thefts trace back to a firmware bug Coinkite introduced in March 2021. That bug moved key creation away from the device’s own hardware source and into a software substitute, cutting the strength of the entropy used from 128 down to as low as 40. That weakness let attackers work out private keys offline and empty out addresses guarded by only one key, without ever touching the physical device. The thefts tied to this bug began on July 30.

Coinkite’s Fix and Its Limits

Coinkite has since changed its firmware. The current versions, Mk4/Mk5 5.6.2 and Q 1.5.2Q, now require owners to supply their own source of chance through key presses, rolls of a die, or coin throws.

An update alone cannot repair a key that was already made under the faulty version. Anyone whose wallet came from the affected firmware has to make a brand new key and move their coins over to it.

Coinkite chief executive Rodolfo Novak apologized in an open letter on July 31, saying the company would have to work to win back its users’ confidence. A full technical review from Coinkite is still being prepared.

The Wider Picture

Monday’s Galaxy Research thread also flagged a previously unknown holding fed by 58 separate addresses. Galaxy said the cause is still open but believes it belongs to another Coldcard victim. If confirmed, that would push the exploit’s published total to about 1,806 BTC, or $143.9 million.

Galaxy said in August it was also watching a fourth wave, not yet confirmed, worth 638.5 BTC, which would carry the full count past 2,400 BTC. Galaxy added it had seen no attacker activity since August 6.

Wave Detail
Wave 3 97.09 BTC moved, about 45% of that wave’s total
New 58-address holding Not yet confirmed as tied to the exploit
Wave 4 Not yet confirmed, worth 638.5 BTC
All waves combined 82% of stolen Bitcoin still unmoved

Across all waves of the exploit, 82% of the stolen Bitcoin has still not moved.

For now, most of the stolen Bitcoin from the Coldcard exploit sits exactly where the attackers first put it.

Source: decrypt.co

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.