All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Coldcard hackers move 64 BTC, 200 ETH to mixers

Created at 6 Aug · 11:31 AM1 source↑ Market-relevant
IN SHORT

Hackers linked to the Coldcard exploit have transferred approximately 64 Bitcoin and 200 Ether to cryptocurrency mixing protocols, according to CertiK. While some funds were laundered via Wasabi Wallet and Tornado Cash, most stolen assets remain in attacker-controlled wallets.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

64 BTCBitcoin transferred to mixers
$4.17 millionValue of Bitcoin transferred
200 ETHEther transferred to mixers
$380,000Value of Ether transferred
March 2021Date of firmware vulnerability
40 bitsWeakened key strength
128 bitsOriginal key strength
$100 millionEstimated losses from Coldcard exploit
7,300Victim wallets affected

Who's Involved

CertiK
Blockchain security platform that identified the transfers
Wasabi Wallet
Cryptocurrency mixing protocol used for Bitcoin transfer
Tornado Cash
Cryptocurrency mixing protocol used for Ether transfer
TRM Labs
Blockchain intelligence company analyzing attacker behavior
Galaxy Digital
Provided analysis on total losses and number of attackers
Haseeb Qureshi
Managing partner at Dragonfly, commented on AI's role

↳ Why This Matters

The use of cryptocurrency mixers highlights the ongoing challenge of tracing illicit funds in the digital asset space, even as blockchain analytics tools improve. The vulnerability exploited in Coldcard wallets also raises concerns about the security of hardware wallets and the potential role of AI in discovering such weaknesses.

Key facts

  • Approximately 64 Bitcoin, valued at $4.17 million, and 200 Ether, valued at $380,000, linked to the Coldcard exploit were sent to crypto mixing protocols.
  • The Bitcoin was transferred to Wasabi Wallet, and the Ether to Tornado Cash.
  • Blockchain security platform CertiK reported the transfers.
  • Most of the stolen funds remain pooled in attacker-controlled addresses.
  • A firmware bug from March 2021 weakened seed randomness on some Coldcard wallets, making them vulnerable to brute-force attacks.
  • Analysis by TRM Labs suggests multiple attackers may be behind the exploit.

Hackers associated with the recent Coldcard exploit have moved approximately 64 Bitcoin, valued at $4.17 million, and 200 Ether, worth $380,000, to cryptocurrency mixing services. The Bitcoin was sent to Wasabi Wallet, while the Ether was transferred to Tornado Cash, according to blockchain security platform CertiK.

Crypto mixers like Tornado Cash pool and scramble funds from multiple users, making it difficult to trace the origin and destination of cryptocurrencies, thereby hindering asset recovery efforts. Despite these transfers, on-chain tracing by TRM Labs indicates that the majority of the stolen funds remain in a limited number of attacker-controlled addresses with minimal mixing attempts.

CertiK suggests that the transfers might be from a smaller exploiter or copycats, a notion supported by TRM Labs' analysis of transaction constructions, which hints at multiple attackers. Galaxy Digital previously identified at least 15 different attackers exploiting the Coldcard vulnerability, with total losses estimated at $100 million to $130 million.

The Coldcard exploit was reportedly due to a firmware bug from March 2021 that weakened seed randomness, reducing key strength to 40 bits from 128 bits, making it susceptible to brute-force attacks without physical access. Some reports suggest that AI models may have rediscovered this vulnerability.

Frequently asked questions

The Coldcard exploit was a security breach that allowed hackers to drain at least $100 million in Bitcoin from victim wallets due to a firmware vulnerability weakening seed randomness.

Cryptocurrency mixers, such as Tornado Cash and Wasabi Wallet, are services that pool and scramble digital assets from multiple users to obscure the on-chain link between senders and recipients.

Despite some funds being sent to mixers, the majority remain in attacker-controlled wallets, indicating limited attempts to launder the full amount of stolen assets.

A firmware bug from March 2021 weakened the seed randomness on some Coldcard wallets, reducing the key strength and making it vulnerable to brute-force attacks.

What Happens Next

01Further analysis by blockchain security firms to track remaining stolen funds.
02Potential for additional copycat exploits or further fund movements.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence
CME Headlines
  • Amendments to the Strike Price Listing Schedule for all Hourly Event Contract Swaps on Ether
    5 Aug · 7:15 PM

How It Developed

Hackers behind the Coldcard exploit transferred 64 Bitcoin and 200 Ether.
The Bitcoin was sent to Wasabi Wallet, and the Ether to Tornado Cash.
Blockchain security platform CertiK identified the transfers.
Most stolen funds remain in attacker-controlled wallets with limited mixing.
Analysis suggests multiple attackers may be involved due to differing transaction constructions.
A firmware bug from March 2021 weakened seed randomness on some Coldcard wallets, making them vulnerable.
Reports suggest AI models may have rediscovered the vulnerability.

Sources

T1
Coldcard hackers transfer 64 BTC and 200 ETH to cryptocurrency mixersHackers behind the Coldcard exploit transferred millions in digital assets to cryptocurrency mixers, while most stolen funds remained traceable in attacker-controlled wallets.Cointelegraph

Related Stories

Coldcard exploit could boost demand for regulated bitcoin exposure, analysts say
5 Aug · 3:51 PM
Bitcoin, Ether Gain as Traders Favor Largest Crypto Tokens
6 Aug · 10:51 AM
Bitcoin Red Team Finds Nearly 5,000 Security Issues in Ecosystem Audit
6 Aug · 1:20 AM
Binance sues RedotPay over alleged $473 million user losses
5 Aug · 12:11 PM
Bitcoin Red Team Flags 85 Critical Bugs in 390 Projects Using AI
6 Aug · 8:06 AM