en

A New Wave Has Begun at Coldcard, One of the Largest Bitcoin Wallet Hacks in Recent Times—The Losses Are Mounting

image
rubric logo Bitcoin
1
like dislike fud 5

Galaxy Research announced the detection of a third wave of attacks believed to target addresses created on Coldcard devices. The latest wave reportedly resulted in the withdrawal of 207.7294 $BTC, bringing the total loss to 1,367.05 $BTC, or approximately $88.6 million, across 4,585 addresses.

According to the research firm, the first two waves of attacks exhibited largely similar on-chain behavior. Both waves saw funds being transferred to a small number of shared collection addresses, P2WPKH addresses being used, and wallets originating from different derivation paths being targeted. The approximately 27-hour interval between the two waves and the similarities in transaction structures suggest that the attacks may have been carried out by the same person or group.

However, Galaxy Research emphasized that there were differences between the first two waves in terms of transaction fees and “replace-by-fee” signals, therefore it could not be definitively proven that the same attacker was involved.

The Third Wave May Point to a Different Attacker

According to Galaxy Research, the third wave of attacks differs from the previous two in almost every measurable behavioral characteristic. Instead of using shared collection addresses in the first attacks, the third wave was found to have created a separate target address for each victim.

It was stated that the Bitcoins stolen in the third wave were held in P2WSH addresses instead of P2WPKH addresses, and that an average of 6.37 victim addresses were aggregated in each dump. In the first wave of the attack, each transaction targeted only a single victim address. It was also stated that the third wave only scanned addresses in the default derivation path.

Researchers noted that these changes could stem from the same attacker re-engineering their tools to make on-chain tracing more difficult. However, it was also noted that it is possible a second attacker targeting the same vulnerable key pool emerged after information about the Coldcard vulnerability was made public.

Galaxy Research reported that on-chain data did not allow for a definitive distinction between these two scenarios. The company stated that while it was certain each attack wave was managed by a single operator, it could not be definitively said that all three waves were linked to the same attacker.

Related News Michael Saylor: “We Never Said We'd Never Sell Bitcoin”

Bitcoins in Attacker Addresses Have Not Yet Moved

According to Galaxy Research’s calculations, the attackers control a total of 1,366.3865 $BTC. It is stated that not all of the final attacker addresses to which these Bitcoins, worth approximately $88.6 million, were transferred have yet spent them on the chain.

Graph showing the total amount of Bitcoin lost in the attacks. Source: Galaxy Research

Block-by-block analysis revealed that addresses were dumped en masse during attack waves. The absence of any dumping operations in intermediate blocks within each wave that could be attributed to the attackers indicated that the operations were sent to the network in groups, not continuously.

It was noted that the losses were mostly concentrated in wallets with balances below 1 $BTC in terms of address count, but addresses with larger balances were decisive in terms of total value. Galaxy Research assessed that this distribution resembled individual users’ own custodial wallets rather than institutional custodial services.

The study also indicated that the vulnerable Coldcard software was released on March 17, 2021, around block 674,951 of the Bitcoin network. Galaxy Research stated that none of the Bitcoins identified as stolen in the first three waves of attacks were created before this block.

*This is not investment advice.