Coldcard Attacker Moves Nearly Half of Stolen Bitcoin as Losses Top $143 Million
The operator behind the Coldcard hardware wallet breaches has begun moving nearly half of the stolen bitcoin, highlighting persistent security risks in legacy crypto infrastructure.
The attacker behind the recent Coldcard hardware wallet breaches has moved 45 percent of the stolen assets from the third wave of exploits. Galaxy Research noted the operator is systematically shifting the compromised funds, signaling an active phase of laundering or liquidation.
Total losses have now reached 1,806 bitcoin, valued at approximately $143.9 million at current market prices. This updated figure incorporates a previously unknown vault comprising 58 addresses that the exploiter recently co-spent, according to Monday’s analysis.
Galaxy Research observed that the attacker is moving the stolen coins in descending order of size. The largest 11 vaults have already been transferred, while the next 10 untouched vaults hold 30.81 bitcoin. Smaller holdings, specifically ranks 61 to 293, hold a combined 33.77 bitcoin.
These breaches originated from a firmware bug introduced by Coinkite in 2021. The flaw reduced the randomness used to generate wallet seeds, enabling the attacker to brute-force private seed phrases. This allowed the remote draining of single-signature addresses without any physical access to the devices.
Despite the recent movements, 82 percent of the total exploited funds remain in the attacker’s original addresses. By mid-August, analysts had already identified roughly 1,779 bitcoin stolen from 190 victims across more than 8,600 addresses.
Lingering Infrastructure Risks
This ongoing liquidation process underscores the long-tail financial risks associated with legacy hardware vulnerabilities in the digital asset sector. Investors and institutional custodians must recognize that cryptographic flaws can remain dormant for years before being weaponized at scale, threatening user funds long after initial deployment.
Market participants are now closely monitoring the blockchain for signs of a potential fourth wave of attacks. Galaxy Research has flagged this possibility, though it remains unconfirmed as the current laundering operation continues to unfold across the network.