Skip to content
Active Currencies: 18,453
Market Cap: $2.277T
Bitcoin Dominance: 56.55%
24h Market Cap Change: $0.55

Coldcard exploit reveals years-long Bitcoin theft campaign — Details

Why have losses continued 5 years after the vulnerable Coldcard firmware was released in 2021?

Coldcard exploit reveals years-long Bitcoin theft campaign — Details

It’s been 18 days, and the impact of the Coldcard exploit starting on 30th July is still being felt. Galaxy Research spoke to more than 200 victims on 16th August to understand the intelligence behind the attack. 

The compromised coins were produced on the day the vulnerable Coldcard firmware was released. This happened on 17th March 2021, when Bitcoin [BTC] had reached a block height of 674,951. The timing is what makes this attack noteworthy since it also links the exploit to a seed-generation flaw.

In such types of flaws, the illicit actors usually predict or forge the stolen wallet seed entropy. 

losses have exceeded $115M
Source: Galaxy Research

An assessment of the losses

Here, it’s worth noting that the time period between 2021 and 2022 saw the largest concentration of stolen addresses.

Also, only a small percentage of the 8,680 addresses in Galaxy’s published theft set have been directly connected to victims who reported losses. This, even though they hold approximately 1,778.6 BTC

Count of addresses with coins stolen
Source: Galaxy Research

Additionally, all 192 individuals reported losses involving addresses in the dataset that was made public, which includes roughly 1,790 addresses and 714.8 Bitcoin.

AMBCrypto recently reported that these losses surpassed 1,596 BTC worth more than $100 million across roughly 7,300 addresses. Given Bitcoin’s price on 16th August though, the total losses have now surpassed $115 million.

What do we know about the attackers?

A few “fingerprints” were found during the investigation. These fingerprints were based on transaction behavior such as block timing, fees, lock times, RBF/sequence settings, transaction structure, and destination addresses.

Wave 1, for instance, stole roughly 1,082.65 BTC from blocks 960,183–960,191. They typically moved one victim per transaction into four collection addresses.

Attacker wallet fingerprint
Source: Galaxy Research

Similarly, Wave 3 managed 63 victims and Wave 2 handled 19 while Footprint E batched up to 795 victims per transaction, with a median of 118.

Patterns of destination also differed, with some groups dispersing funds over hundreds of locations while others concentrated them into a few addresses.


Final Summary

  • Exploit affected 192 individuals, with roughly 714.8 Bitcoin compromised.
  • Most of these significant losses happened between 2021 and 2022.
Disclaimer: AMBCrypto's content is meant to be informational in nature and should not be interpreted as investment advice. Trading, buying or selling cryptocurrencies should be considered a high-risk investment and every reader is advised to do their own research before making any decisions.

Ishika Kumari

Journalist

Ishika Kumari is a Crypto Analyst at AMBCrypto, specializing in regulatory developments, market dynamics, and blockchain’s real-world impact. She breaks down complex protocols and legislation into practical, easy-to-understand insights.

AMBCrypto was founded in 2018 with a mission to simplify and bring the latest blockchain and cryptocurrency news to our readers. We have quickly grown into the digital news source for an emerging generation of cryptocurrency enthusiasts, reaching more than a million readers on a monthly basis, across the globe.