Home Crypto Coldcard attacker holds 1,159 BTC as mixing starts

Coldcard attacker holds 1,159 BTC as mixing starts

4
0



Most of the Bitcoin stolen through the COLDCARD wallet flaw remains unmoved, but on-chain investigators have detected a separate attacker beginning to route smaller amounts through a mixer.

Summary

  • The largest known COLDCARD attacker controls 1,159 BTC across seven addresses.
  • None of the 1,159 BTC has entered mixers or been transferred to an identifiable cash-out service.
  • A separate attacker sent 64 BTC toward a mixer, initially mixing about 10 BTC.
  • Investigators have distributed roughly 600 flagged addresses to law enforcement, exchanges, and analytics firms.

COLDCARD attacker leaves 1,159 BTC untouched

Galaxy Research said the largest known theft connected to the COLDCARD vulnerability involved 1,159 BTC. The funds remain spread across seven addresses associated with the attacker and have not moved since the initial sweep.

The Bitcoin was stolen within 41 minutes, according to the latest on-chain monitoring cited by Bitcoin News. Investigators have not detected transfers from the seven addresses to exchanges, mixers or other services commonly used to obscure stolen funds.

The assets are therefore better described as unmoved rather than technically frozen. Bitcoin transactions cannot be stopped at the protocol level merely because an address has been flagged.

However, the attacker could face difficulties converting the funds into fiat or other assets. Law enforcement agencies, cryptocurrency exchanges and blockchain analytics companies have reportedly flagged about 600 addresses connected with the wider theft.

Any transfer to a compliant exchange could trigger transaction monitoring controls and requests for information about the account receiving the Bitcoin.

Smaller attacker begins mixing stolen Bitcoin

Separate on-chain activity suggests another attacker has started attempting to obscure part of the stolen funds.

Analysts tracked 64 BTC entering a transaction flow linked to a mixer. Approximately 10 BTC was initially mixed, while about 54 BTC returned as change. The remaining funds were subsequently divided into outputs of roughly 7 BTC each for further mixing.

Mixers combine or restructure transactions to make it harder to connect the original source of cryptocurrency with its eventual destination. However, they do not guarantee that funds will become untraceable.

Analysts said the relatively large and consistently sized outputs make this laundering attempt easier to follow. Investigators can continue monitoring the transactions as the Bitcoin passes through additional addresses.

The activity also appears separate from the seven-address cluster holding 1,159 BTC. Previous reporting found that multiple attackers may have exploited the same wallet weakness, meaning movements from one cluster should not automatically be attributed to every COLDCARD theft.

Galaxy previously tracked 1,596 stolen BTC

As previously reported by crypto.news, Galaxy Research confirmed that attackers stole 1,596 BTC from approximately 7,300 addresses across three attack waves. It also identified 14 smaller incidents connected to the same seed-generation flaw.

A suspected fourth wave could raise the total to approximately 2,055 BTC, although Galaxy had not confirmed those additional losses through sufficient victim reports.

The vulnerability resulted from a firmware error that weakened the randomness used to generate wallet seed phrases. Attackers could reproduce possible seeds offline, derive their Bitcoin addresses, and compare them with addresses visible on the blockchain.

They did not need physical access to the devices, their PINs, or the Bitcoin network itself. The underlying Bitcoin protocol was not compromised.

Coinkite has released corrected firmware, but an update cannot secure a seed phrase generated using a vulnerable version. Affected users must create an entirely new seed and transfer their Bitcoin to addresses derived from it.

US investigators monitor flagged addresses

Galaxy previously said it shared confirmed attacker and victim addresses with US law enforcement agencies, exchanges and cyber-investigation groups. The expanding address list could help authorities identify stolen funds when attackers attempt to use regulated services.

Still, recovering the Bitcoin remains uncertain. An attacker may move funds through several addresses, mixers, decentralized platforms or services outside US jurisdiction before attempting to convert them.

The latest mixer activity gives investigators a new transaction trail to follow, while the 1,159 BTC held by the largest known attacker remains exposed to continuous public monitoring.





Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here