Coldcard Bitcoin Thief Likely Used Top Blockchain Services Provider: Report
Bitcoin Magazine Coldcard Bitcoin Thief Likely Used Top Blockchain Services Provider: Report Since over $70 million in Bitcoin was stolen yesterday by an attack that exploited a fault in the Coldcard’s system, it has bee...
Watchlist
Published in the last two hours. A tracked entity is involved.
Bitcoin Magazine
Coldcard Bitcoin Thief Likely Used Top Blockchain Services Provider: Report
Since over $70 million in Bitcoin was stolen yesterday by an attack that exploited a fault in the Coldcard’s system, it has been reported that the thief used a top blockchain services provider for help.
Writing on X Friday, engineer at payments company Block, Clay Garrett, said that the provider — who he did not name at the request of the services provider — had been contacted after finding blockchain movements matched the “suspected workflow” of the attacker.
“During our investigation of the Coldcard drain yesterday, we identified an unusual pattern in the sweeps,” Garrett said.
“That pattern led us to a hypothesis that has since been confirmed: the operator used a paid account at a well-known blockchain-services provider to query the source addresses and perform other related activity during the sweeps,” Garrett continued, adding that the authorities had been notified.
Galaxy Digital’s research arm also wrote on X that the thief had an unusual pattern of moving the coins.
“The pattern tells us these were all the same attacker — it does not capture the attack itself, which looks the same as if a coin owner chose to move coins,” the company said, adding that Bitcoiners should move funds out of single-signature Coldcard addresses and into secure custody.
After over $35 million in Bitcoin was drained from wallets on Thursday, Coinkite said that a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator.
This allowed private keys for many single-signature wallets (especially those created without dice rolls or a strong BIP-39 passphrase) predictable enough for attackers to brute-force.
Later on Friday, Coinkite admitted all of its models were vulnerable following more thefts. Over $70 million has so far been swiped and engineers have warned that more Bitcoin addresses could be at risk.
The company makes a number of Bitcoin products, including cold storage hardware wallets.
This post Coldcard Bitcoin Thief Likely Used Top Blockchain Services Provider: Report first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on Bitcoin MagazineRelated market context
Block traces COLDCARD attacker to blockchain services provider after $38M Bitcoin theft
The incident underscores the critical need for rigorous firmware testing and swift vulnerability disclosures to protect digital as...
Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen
Bitcoin Magazine Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen The popular Bitcoin hardware wallet...
Coldcard attack: 25 minutes, 500 wallets, $38M in BTC gone
Someone likely used AI to drain almost 600 BTC, worth $38 million, from roughly 500 dormant wallets yesterday as part of a seed ph...
Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus
A Coldcard security issue has put Bitcoin hardware-wallet safety back under the microscope after reports that a firmware flaw affe...
Coinkite Warns Coldcard Mk3 Owners After Reports of $38M Bitcoin Loss
Coinkite issued a security advisory Thursday warning owners of its Coldcard Mk3 hardware wallet that funds tied to certain firmwar...
Coinkite reports $38M in Bitcoin drained due to Coldcard key generation flaw
The incident underscores the critical need for robust security measures in hardware wallets, potentially boosting multi-signature...