Coldcard Theft Update: Large Stash Remains Still as Mixing Begins
While the primary perpetrator behind the Coldcard wallet exploit sits on a massive 1,159 BTC fortune, a secondary attacker has begun routing stolen assets through a mixer. On-chain investigators continue to monitor the stagnant funds, which remain flagged across exchanges and law enforcement databases to prevent liquidation.
The largest cluster of stolen Bitcoin—totaling 1,159.42 BTC—has remained effectively frozen in seven addresses since the initial breach. On-chain monitoring confirms that despite the high volume of assets, which are valued at approximately $72.7 million, none of these funds have reached mixers or identifiable cash-out services. Analysts note that these assets are technically unmoved rather than locked, as the Bitcoin protocol itself cannot halt transactions based on address blacklisting.
Separately, a different actor has initiated laundering efforts for a smaller haul of 64 BTC. On-chain data shows this attacker routing the funds through a mixer, with initial transactions processing about 10 BTC. The remainder has been structured into smaller, consistently sized outputs of roughly 7 BTC, a pattern that investigators are currently tracking. Galaxy Research indicates that these distinct movements suggest multiple attackers likely exploited the same firmware vulnerability.
With approximately 600 addresses now flagged by analytics firms and shared with authorities, the path to fiat conversion is increasingly narrow. The vulnerability, which stemmed from a flawed random number generator in Coinkite’s firmware, allowed attackers to replicate seed phrases offline without physical device access. Although the company has released a patch, users remain at risk unless they generate entirely new seeds, as the update cannot retroactively secure assets created under the compromised firmware.
Comments (0)
No comments yet. Be the first!