Key facts
- Approximately 64 Bitcoin, valued at $4.17 million, and 200 Ether, valued at $380,000, linked to the Coldcard exploit were sent to crypto mixing protocols.
- The Bitcoin was transferred to Wasabi Wallet, and the Ether to Tornado Cash.
- Blockchain security platform CertiK reported the transfers.
- Most of the stolen funds remain pooled in attacker-controlled addresses.
- A firmware bug from March 2021 weakened seed randomness on some Coldcard wallets, making them vulnerable to brute-force attacks.
- Analysis by TRM Labs suggests multiple attackers may be behind the exploit.
Hackers associated with the recent Coldcard exploit have moved approximately 64 Bitcoin, valued at $4.17 million, and 200 Ether, worth $380,000, to cryptocurrency mixing services. The Bitcoin was sent to Wasabi Wallet, while the Ether was transferred to Tornado Cash, according to blockchain security platform CertiK.
Crypto mixers like Tornado Cash pool and scramble funds from multiple users, making it difficult to trace the origin and destination of cryptocurrencies, thereby hindering asset recovery efforts. Despite these transfers, on-chain tracing by TRM Labs indicates that the majority of the stolen funds remain in a limited number of attacker-controlled addresses with minimal mixing attempts.
CertiK suggests that the transfers might be from a smaller exploiter or copycats, a notion supported by TRM Labs' analysis of transaction constructions, which hints at multiple attackers. Galaxy Digital previously identified at least 15 different attackers exploiting the Coldcard vulnerability, with total losses estimated at $100 million to $130 million.
The Coldcard exploit was reportedly due to a firmware bug from March 2021 that weakened seed randomness, reducing key strength to 40 bits from 128 bits, making it susceptible to brute-force attacks without physical access. Some reports suggest that AI models may have rediscovered this vulnerability.